Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer needs to implement a solution to detect and alert on suspicious API calls in an AWS account. Which TWO AWS services should be integrated to achieve this? (Choose two.)

⚠ Common exam trap

SCS-C02 often tests the pairing of CloudTrail (the data source) with GuardDuty (the analyzer), tempting candidates to pick AWS Config or Inspector, which address compliance and vulnerability scanning rather than threat detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail (C) is correct because it records API activity in the account as management and data events, providing the raw log source needed to detect suspicious API calls. Amazon GuardDuty (E) is correct because it continuously analyzes CloudTrail management events (along with VPC Flow Logs and DNS logs) using threat intelligence and machine learning to detect and alert on suspicious API activity. Together, CloudTrail supplies the API call records and GuardDuty generates the findings and alerts. AWS Config (A) evaluates resource configuration compliance rather than detecting suspicious API behavior, Amazon Inspector (B) scans workloads for software vulnerabilities and network exposure, and AWS Trusted Advisor (D) provides best-practice recommendations, so none of these fulfill the detection-and-alert requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a configuration management and compliance auditing service that records the state of AWS resources and evaluates them against desired JSON configuration rules. While it can detect configuration changes and flag resources that violate compliance policies, it does not analyze the context of API calls—who made the call, from where, or whether the intent or pattern suggests a threat. Config lacks the machine-learning-based anomaly detection and threat intelligence needed to identify suspicious API activity, so it is not the correct choice for this threat-detection requirement.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that scans EC2 instances and container images for software vulnerabilities, network exposure, and unintended network accessibility. It does not ingest or analyze CloudTrail logs or API call patterns, so it cannot detect suspicious API activity or credential misuse. Inspector findings are based on CVEs and network reachability, not anomalous user or API behavior, which makes it the wrong tool for this requirement.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is an audit service that continuously records all API activity in an AWS account, capturing the calling identity, source IP address, timestamp, request parameters, and response elements. CloudTrail itself is not a threat-detection engine—it simply produces the raw audit logs—but it is a required and correct component because it provides the management-event data that GuardDuty consumes to detect suspicious API calls. Enabling CloudTrail is the necessary first step, and when paired with GuardDuty's analysis engine, it becomes part of a complete detection solution.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor provides best-practice recommendations across cost optimization, performance, security, and fault tolerance using predefined checks, such as whether MFA is enabled on the root account or whether security groups allow unrestricted access. It evaluates account and resource configurations against AWS best practices, not real-time API call patterns, and it does not perform anomaly-based threat detection on CloudTrail events. Therefore, Trusted Advisor cannot detect suspicious API calls or the kind of malicious behavior targeted by this solution.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is a continuous threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to analyze AWS CloudTrail management events, VPC Flow Logs, and DNS logs. It is specifically designed to detect suspicious API calls, such as an unusual EC2 instance launch, IAM role assumption from an unfamiliar IP address, or an S3 bucket policy change made by a potentially compromised credential. GuardDuty produces security findings that can be sent to Security Hub or EventBridge, making it the core service that directly satisfies the requirement to detect malicious API activity.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.