Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to detect when an EC2 instance is terminated in an AWS account. The solution must provide near-real-time notification. Which combination of services should be used?

⚠ Common exam trap

A common mix-up: candidates confuse CloudWatch Alarms (which monitor metrics) with event-driven services like EventBridge, failing to recognize that EC2 termination is an API event, not a metric change, and thus requires CloudTrail as the event source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail and Amazon EventBridge

AWS CloudTrail captures API calls, including TerminateInstances, as management events. Amazon EventBridge can filter these events in near real-time and trigger a notification action (e.g., via SNS or Lambda). This combination provides immediate detection of EC2 termination without polling or delays.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs and Amazon CloudWatch Logs

    Why it's wrong here

    VPC Flow Logs capture network traffic metadata at the elastic network interface level — source/destination IP, ports, protocol, and packet counts — but they do not record EC2 lifecycle API actions such as TerminateInstances or RunInstances. Even when delivered to Amazon CloudWatch Logs, flow log entries only reveal network flows, and termination of an instance may generate no distinct flow-log signature. Therefore, this combination cannot reliably detect when an EC2 instance is terminated.

  • ✓

    AWS CloudTrail and Amazon EventBridge

    Why this is correct

    AWS CloudTrail is the correct service here because it records management events as API calls, including the TerminateInstances action, with details such as the IAM principal, source IP, and request parameters. Amazon EventBridge can consume CloudTrail API events through a rule that matches source=aws.ec2 and eventName=TerminateInstances, then trigger an SNS topic or Lambda function within seconds. This gives a near-real-time, audit-ready detection path that is directly tied to the API request that caused the termination.

  • ✗

    AWS Config and Amazon SNS

    Why it's wrong here

    AWS Config can detect when an EC2 instance is terminated because its configuration recorder observes resource deletion and can trigger evaluation rules, but this is not a real-time API-level mechanism. Config evaluations run on a configuration-change or periodic schedule, which can introduce minutes of delay, and the service requires pre-configuring a recorder, rules, and delivery channels. While SNS can deliver the resulting notification, the overall pipeline is slower and more indirect than CloudTrail plus EventBridge for lifecycle event detection.

  • ✗

    Amazon CloudWatch Alarms and Amazon SNS

    Why it's wrong here

    Amazon CloudWatch Alarms monitor performance metrics such as CPUUtilization, NetworkIn, or StatusCheckFailed, not EC2 lifecycle API calls or instance state changes. When an instance is terminated, its metric data stops flowing and an alarm may eventually enter INSUFFICIENT_DATA, but that is an unreliable side effect rather than a definitive termination event. Using CloudWatch Alarms with SNS would require you to infer termination from missing metrics, which is poor for real-time detection compared to the explicit TerminateInstances API event captured by CloudTrail.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.