Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to analyze VPC Flow Logs to identify traffic to a known malicious IP address. The logs are stored in Amazon S3. Which approach is the most cost-effective for querying the logs?

⚠ Common exam trap

It's easy for candidates to assume loading data into a dedicated database (Redshift) or using a big data framework (EMR) is necessary for analysis, overlooking Athena’s serverless, pay-per-query model that is purpose-built for querying data directly in S3 without data movement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Amazon Athena to query the logs in S3

Amazon Athena is the most cost-effective option because it is a serverless query service that allows you to run SQL queries directly on data stored in S3, including VPC Flow Logs, without needing to load or transform the data. You pay only for the data scanned per query, and with partitioning (e.g., by date or region), you can minimize costs by scanning only relevant log files. This avoids the overhead of provisioning clusters or managing infrastructure, making it ideal for ad-hoc analysis of malicious IP traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Amazon Athena to query the logs in S3

    Why this is correct

    Amazon Athena is the correct choice because it is a serverless, interactive query service that uses standard SQL to query data directly from S3, paying only for the data scanned. VPC Flow Logs stored in S3 can be queried immediately by creating a table in the AWS Glue Data Catalog, with no infrastructure to provision or manage. Athena is optimized for ad-hoc, cost-effective analysis, and its per-query pricing makes it ideal for the intermittent, investigative queries a security engineer typically runs. Partitioning the S3 flow log data by date and using columnar formats further reduces cost and query time.

  • ✗

    Load the logs into an Amazon Redshift cluster

    Why it's wrong here

    Amazon Redshift is wrong because it is a petabyte-scale data warehouse that requires you to provision a cluster (or enable serverless), configure node types, and load the S3 flow logs into tables using COPY commands, adding complexity and operational overhead. Redshift incurs compute and storage costs continuously, even during idle periods between security analyses, making it far more expensive than Athena for occasional ad-hoc queries. While Redshift can query S3 via spectrum or external tables, the initial loading and cluster management are unnecessary for this use case. Redshift is best suited for production reporting and complex analytics on relational data, not for cost-effective point-in-time flow log investigation.

  • ✗

    Use Amazon EMR to run Spark jobs

    Why it's wrong here

    Amazon EMR is wrong because it involves launching a managed Hadoop/Spark cluster, which requires you to provision EC2 instances, configure cluster settings, and manage job execution, all of which incur per-hour costs regardless of how many queries you run. Running Spark jobs on EMR for simple SQL queries over VPC Flow Logs is architectural overkill and introduces significant engineering overhead, such as writing and orchestrating Spark applications or Hive scripts. EMR is designed for large-scale ETL, machine learning, and big-data processing pipelines, not for the lightweight, interactive SQL analysis that Athena provides. Even transient EMR clusters take minutes to start and add latency, making them an inefficient tool for quick security investigations.

  • ✗

    Use Amazon QuickSight to connect to S3

    Why it's wrong here

    Amazon QuickSight is wrong because it is a business intelligence and visualization service designed for building interactive dashboards, charts, and reports, not for running exhaustive SQL queries to extract detailed findings. Although QuickSight can connect to S3 or Athena as a data source, it does not provide a direct SQL query interface to S3; it relies on SPICE or Direct Query to feed visualizations. A security engineer needs to run analytical queries (e.g., filtering by source IP, action, or time range) and inspect raw logs, which QuickSight cannot do efficiently. QuickSight is meant for presenting aggregate data to stakeholders, not for the deep, query-driven log analysis this scenario requires.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.