Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to monitor AWS account activity for suspicious API calls and receive alerts. Which AWS service should the engineer use to meet this requirement?

⚠ Common exam trap

A common mix-up: candidates confuse GuardDuty's threat detection with the ability to monitor and alert on specific API calls, but GuardDuty does not provide customizable metric filters or alarms for arbitrary API patterns; CloudTrail with CloudWatch Alarms is the correct service for that precise requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail with CloudWatch Alarms

AWS CloudTrail records all API calls made to the AWS environment, providing a detailed audit trail of account activity. By sending these logs to Amazon CloudWatch, you can create metric filters that match suspicious API call patterns and trigger CloudWatch Alarms to send notifications via SNS. This combination directly meets the requirement to monitor and alert on specific API calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture network-level metadata about IP traffic crossing elastic network interfaces — source and destination addresses, ports, protocol, packet counts, and allow/deny actions — but they do not record the identity of the caller, the API action performed, or the request parameters. AWS account activity is represented by control-plane API calls such as AssumeRole or CreateUser, and those calls appear nowhere in flow logs because flow logs only see the TCP/TLS connection, not its semantic content. Thus VPC Flow Logs cannot provide the needed API-call monitoring.

  • ✗

    AWS Config with AWS Config Rules

    Why it's wrong here

    AWS Config records the configuration history of AWS resources and evaluates that configuration against AWS Config Rules to flag compliance violations, such as an unencrypted S3 bucket or a security group with an overly permissive rule. However, Config rules assess the state of a resource — what exists and whether it conforms to a policy — rather than capturing the IAM principal or the exact API request that changed it. Since the goal is to monitor account activity as discrete API calls, AWS Config lacks the identity and action-level detail required.

  • ✓

    AWS CloudTrail with CloudWatch Alarms

    Why this is correct

    AWS CloudTrail is the authoritative service for recording API activity: it captures every management and data event with details such as the event name, IAM user or role that made the call, source IP address, request parameters, and response elements. When you send those CloudTrail events to CloudWatch Logs via a trail, you can define a metric filter on a specific pattern — such as eventName for a sensitive action or an errorCode indicating failed access — and attach a CloudWatch Alarm to trigger an SNS notification. That pipeline gives a deterministic, near-real-time alert for account activity, which is exactly what the security engineer needs.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat-detection service that uses machine learning and anomaly detection on data sources like CloudTrail management events, VPC Flow Logs, and DNS logs to generate findings about suspected malicious behavior — for instance, compromised credentials, crypto-mining, or reconnaissance from an external IP. GuardDuty cannot be custom-tuned to alarm on an arbitrary, user-defined API call because its findings are based on learned baselines and built-in threat intelligence, not on literal event-pattern matching. It also does not maintain a complete, queryable audit trail of every API action, so it complements rather than replaces CloudTrail-based activity monitoring.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.