Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to collect and analyze operating system logs from EC2 instances. Which TWO services are required?

⚠ Common exam trap

Many exam-takers confuse Amazon CloudWatch Logs (the destination service) with the CloudWatch Agent (the collection mechanism), thinking that CloudWatch Logs alone can pull logs from EC2 instances without needing an agent installed on the OS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Logs

Amazon CloudWatch Logs is the service that stores, monitors, and accesses operating system logs from EC2 instances. However, to collect and send those logs to CloudWatch Logs, you must install and configure the Amazon CloudWatch Agent on the EC2 instances. The CloudWatch Agent can collect logs from the OS (e.g., /var/log/syslog, /var/log/messages, Windows Event Log) and forward them to CloudWatch Logs for analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs are incorrect for this use case because they capture only network traffic metadata — such as source/destination IPs, ports, protocols, and packet counts — at the VPC, subnet, or elastic network interface level. They do not have visibility inside the EC2 guest OS, so they cannot record OS system logs, application logs, security events, or command execution. Flow Logs provide no mechanism to collect or analyze /var/log/syslog, Windows Event Logs, or other OS-generated log files.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is not a log collection or analysis service; it continuously records and evaluates AWS resource configuration changes and compliance against rules (e.g., whether an instance has the correct security group or IAM role). It operates entirely on the AWS control plane and never installs an agent inside the EC2 instance, so it cannot read OS-level log files or analyze guest operating system events. While Config is useful for auditing infrastructure drift, it does not ingest or store the kind of operational log data the engineer needs.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    Amazon CloudWatch Logs is the correct central service for storing, monitoring, and analyzing OS logs collected from EC2 instances. It receives log data forwarded by the CloudWatch agent and organizes it into log groups and log streams, enabling real-time searching, metric filters, alarms, and querying with Logs Insights. Once OS logs are ingested, the engineer can use CloudWatch Logs to correlate events across instances, build dashboards, and set automated alerts, making it the core analysis platform for the collected logs.

  • ✓

    Amazon CloudWatch Agent

    Why this is correct

    The CloudWatch agent is the correct collection mechanism because it runs inside the EC2 instance and actively reads OS logs and metrics from the guest operating system. It supports syslog, Windows Event Logs, and custom application log files, then forwards them to Amazon CloudWatch Logs for storage and analysis. Without this agent, the OS logs would remain on the instance and would never reach a central service; therefore, it is a necessary component for fulfilling the 'collect' part of the requirement.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is incorrect for this task because it records AWS API call history for the control plane, such as who launched an EC2 instance, modified a security group, or called an AWS service. It does not capture operating system activity, user logins, process executions, or log files within the instance's guest OS. CloudTrail is designed for governance, compliance, and auditing of AWS account actions, but it has no visibility into the internal OS, so it cannot collect or analyze the operating system logs the engineer needs.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.