SCS-C02 Security Logging and Monitoring Practice Question
A security engineer needs to detect when an IAM access key is created for a user and then used from an unusual location. The engineer wants to receive an alert when such activity occurs. Which AWS service should be used to meet this requirement?
⚠ Common exam trap
The trap here is assuming that CloudTrail, which records the API calls, also performs the analysis and alerting; in fact, GuardDuty is the service that analyzes those logs and generates findings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty is a threat detection service that analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to identify malicious or anomalous activity. It can detect unusual access key usage from unexpected locations and generate findings that can be routed to alerting systems. CloudTrail, AWS Config, and Amazon Inspector do not provide this threat detection and alerting capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector assesses EC2 instances and container images for software vulnerabilities and unintended network exposure. It does not monitor IAM access key usage or geographic anomalies. It is unrelated to the requirement of detecting unusual access key activity.
- ✗
AWS Config
Why it's wrong here
AWS Config evaluates resource configurations against desired rules. It can detect when an access key is created if a custom rule is configured, but it does not analyze usage patterns or geographic locations. It is not designed for threat detection or alerting on anomalous API usage.
- ✓
Amazon GuardDuty
Why this is correct
GuardDuty continuously monitors CloudTrail management events, VPC Flow Logs, and DNS logs to detect threats. It can identify anomalous behavior such as an IAM access key being used from an unusual geographic location. GuardDuty generates findings that can trigger alerts via CloudWatch Events or SNS, meeting the requirement.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records API activity, including CreateAccessKey and usage of access keys, but it does not analyze patterns or generate alerts for unusual locations. It provides the raw log data that other services can analyze. CloudTrail alone cannot meet the requirement to receive an alert.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.