SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer suspects that an EC2 instance is communicating with a known malicious IP address. The engineer needs to capture the full network packets for analysis. Which approach should be taken?
⚠ Common exam trap
Watch out — candidates often confuse VPC Flow Logs (which provide metadata only) with full packet capture, leading them to choose Option C, but VPC Flow Logs cannot capture packet payloads required for deep forensic analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use VPC Traffic Mirroring to mirror the instance's ENI to a monitoring appliance.
VPC Traffic Mirroring captures and copies all network traffic from an EC2 instance's Elastic Network Interface (ENI) and forwards it to a monitoring appliance (e.g., a security appliance or packet analyzer) for full packet-level analysis. This is the only option that provides raw, full network packets (including headers and payloads) without impacting the instance's performance or requiring software installation on the instance itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS Security Hub to detect and capture malicious traffic.
Why it's wrong here
AWS Security Hub is a central aggregation service that collects and prioritizes findings from services like GuardDuty, Inspector, and Macie, giving you a cross-account security posture view. It does not perform packet capture or inspect raw traffic; it can only display alerts generated by other tools. To actually detect and capture malicious traffic, you would need a packet-level mechanism such as VPC Traffic Mirroring, not Security Hub.
- ✗
Install the Amazon CloudWatch agent on the instance to capture network logs.
Why it's wrong here
The Amazon CloudWatch agent is designed to collect operating-system-level metrics and log files from an EC2 instance, such as CPU utilization, memory usage, and application logs. It has no capability to tap into the instance's Elastic Network Interface (ENI) or capture network packets, so it cannot provide network traffic logs. Even with the agent publishing custom metrics, it remains a host-level monitoring tool, not a network capture tool.
- ✗
Enable VPC Flow Logs on the subnet and analyze the logs.
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic at the subnet, ENI, or VPC level, including source and destination IP addresses, ports, protocol, and byte counts. While this is useful for identifying patterns like unusual connections, it does not record the actual packet contents or payloads, so deep packet inspection is impossible. Flow Logs alone cannot capture the malicious traffic's data, making them insufficient for the investigation described.
- ✓
Use VPC Traffic Mirroring to mirror the instance's ENI to a monitoring appliance.
Why this is correct
VPC Traffic Mirroring copies live traffic from a source ENI and sends it to a designated monitoring appliance or security tool, enabling full packet capture and deep packet inspection. Because it operates at the hypervisor level, it can see every packet, including payloads, without installing agents on the instance. This allows the security engineer to analyze the exact malicious traffic and is the correct method for capturing full network data from the EC2 instance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.