Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer notices suspicious API calls from an EC2 instance that has an IAM role attached. The engineer wants to quickly determine if the instance's credentials have been compromised and are being used from an external IP address. What is the most efficient way to detect this?

⚠ Common exam trap

Watch out — candidates often assume manual log analysis (CloudTrail or VPC Flow Logs) is the fastest approach, but GuardDuty provides automated, real-time detection specifically for this exfiltration pattern, making it the most efficient choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Amazon GuardDuty and look for the finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration'.

Amazon GuardDuty's finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' is specifically designed to detect when EC2 instance credentials (from an IAM role) are being used from an external IP address. GuardDuty analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to identify anomalous API calls where the source IP is outside the VPC, indicating credential exfiltration. This is the most efficient method as it provides a pre-built, automated detection without manual log analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check VPC Flow Logs for traffic from the instance to unusual destinations.

    Why it's wrong here

    VPC Flow Logs record network traffic metadata such as source/destination IPs, ports, and protocols, but they do not capture IAM identity information or the role used. Because the suspicious API calls are made with the instance's temporary credentials from an external attacker, these calls will not correspond to traffic from the instance's network interface, so flow logs cannot reveal the credential exfiltration. Additionally, flow logs fail to log API-level actions, making them a poor source for detecting unauthorized IAM activity.

  • ✗

    Review AWS CloudTrail logs for the instance's IAM role and look for source IP addresses outside the VPC.

    Why it's wrong here

    While CloudTrail does log API calls made by the instance's IAM role and includes the source IP address, relying on manual log review for this detection is inefficient and prone to delays. Attackers can also use the exfiltrated credentials from a range of source IPs, and a source IP outside the VPC is not definitive proof of compromise because legitimate access may originate from various locations. The proper approach is automated analysis that correlates abnormal API usage patterns, such as GuardDuty, rather than manually inspecting CloudTrail events.

  • ✓

    Enable Amazon GuardDuty and look for the finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration'.

    Why this is correct

    Amazon GuardDuty is the correct choice because it automatically monitors CloudTrail events, VPC Flow Logs, and DNS logs using threat intelligence and machine learning to detect anomalies. The specific finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' is designed to identify when EC2 instance role credentials are being used from an external source or in an unusual pattern, indicating exfiltration. This automated detection provides real-time alerts, which is far more effective than manual analysis for this type of security incident.

  • ✗

    Use IAM Access Analyzer to review the trust policy of the instance's IAM role.

    Why it's wrong here

    IAM Access Analyzer is a tool for analyzing resource-based policies and trust policies to identify whether they grant access to external principals, but it does not monitor active API call behavior. It cannot detect that an instance's credentials are being misused or exfiltrated, as it only performs static policy analysis. Therefore, it is irrelevant for investigating suspicious API calls and won't help in identifying the credential exfiltration incident.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.