Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to monitor for unusual outbound network traffic from an EC2 instance. Which AWS service provides this capability?

⚠ Common exam trap

A common mix-up: candidates confuse the CloudWatch Logs agent (which sends application logs) with VPC Flow Logs (which capture network traffic metadata), leading them to select Option A because they think 'monitoring logs' implies network visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Flow Logs

VPC Flow Logs capture metadata about IP traffic going to and from network interfaces in a VPC, including source/destination IPs, ports, protocols, and packet counts. This allows a security engineer to analyze outbound traffic patterns from an EC2 instance and detect anomalies such as data exfiltration or communication with known malicious IPs. The logs can be published to Amazon CloudWatch Logs or Amazon S3 for further analysis with tools like Amazon Athena or third-party SIEMs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch Logs agent

    Why it's wrong here

    The CloudWatch Logs agent is a lightweight daemon installed on EC2 instances to forward local application and OS log files to Amazon CloudWatch Logs. It operates at the instance OS level and captures only what the application writes to disk; it does not sniff network interfaces or record connection-level metadata. Consequently, it cannot be used to detect unusual outbound network connections because it lacks visibility into TCP/UDP packet headers, flow records, or destination IP addresses beyond what an application itself logs.

  • ✓

    VPC Flow Logs

    Why this is correct

    VPC Flow Logs are the native AWS feature that captures IP traffic information for network interfaces in a VPC, recording metadata such as source and destination IP addresses, source and destination ports, protocol, and whether the traffic was accepted or rejected. These logs can be published to Amazon CloudWatch Logs or Amazon S3, where they can be analyzed with CloudWatch Logs Insights, Athena, or third-party tools to detect anomalous outbound connections like data exfiltration or beaconing. Because they capture all network flows at the ENI level, they are the appropriate service for monitoring unusual outbound traffic.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management and automated security assessment service that scans Amazon EC2 instances and container images for software vulnerabilities, unintended network exposure, and deviations from security best practices. While it can evaluate network reachability between resources, it performs point-in-time assessments rather than continuous network flow capture. It cannot tell you about outbound connections that occur after the assessment or provide real-time visibility into unusual traffic patterns, so it is not the right tool for monitoring outbound network activity.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config provides a detailed inventory of AWS resources and records configuration changes over time, allowing you to evaluate resource compliance against predefined or custom rules. It can track changes to security group rules or network ACLs, but it does not inspect or log actual network traffic traversing the VPC. Since unusual outbound activity is an operational event involving data flows, not a configuration change, AWS Config lacks the telemetry needed to detect such behavior.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.