SCS-C02 Security Logging and Monitoring Practice Question
A security team has enabled AWS CloudTrail in all regions and is delivering logs to an S3 bucket. The team has also enabled S3 server access logging for the CloudTrail bucket. The team needs to detect any unauthorized access to the CloudTrail logs. Which combination of services should the team use to achieve near-real-time detection?
⚠ Common exam trap
Many exam-takers confuse AWS CloudTrail Insights (which analyzes management events for anomalies) with GuardDuty (which provides broader threat detection including S3 data events), leading them to choose Option A despite its lack of near-real-time S3 access detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty and Amazon CloudWatch Events
Amazon GuardDuty continuously monitors S3 data plane events, including CloudTrail log delivery and S3 server access logs, to detect suspicious API calls or unauthorized access patterns. Amazon CloudWatch Events (now part of Amazon EventBridge) can trigger near-real-time alerts when GuardDuty generates findings, enabling immediate response. This combination provides the required near-real-time detection without relying on batch analysis or configuration rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail Insights and Amazon CloudWatch
Why it's wrong here
AWS CloudTrail Insights is a machine-learning feature that identifies unusual API activity in management events, such as spikes in error rates or anomalous IAM actions, not malicious S3 object-level access. It does not inspect or correlate S3 data events like GetObject or PutObject for threat signatures, and Amazon CloudWatch is purely a monitoring/alerting service that has no built-in security detection engine. Together, these services cannot determine whether S3 access patterns are malicious, so they fail the real-time detection requirement.
- ✓
Amazon GuardDuty and Amazon CloudWatch Events
Why this is correct
Amazon GuardDuty is a continuous threat detection service that consumes AWS CloudTrail S3 data events, VPC flow logs, and DNS logs to identify suspicious S3 access, such as requests from unusual geographies, compromised credentials, or bucket exfiltration attempts. When a finding is generated, GuardDuty publishes it to Amazon CloudWatch Events (now part of Amazon EventBridge), enabling automated notification through SNS or invocation of Lambda for remediation. This end-to-end pipeline provides the real-time, actionable alerting required for S3 access anomalies.
- ✗
Amazon Athena and Amazon QuickSight
Why it's wrong here
Amazon Athena is an interactive SQL query engine that runs ad-hoc queries against stored S3 access logs or CloudTrail logs, which is useful for post-incident forensics but does not continuously ingest or analyze new log events as they arrive. Amazon QuickSight is a visualization/dashboard service that only displays data prepared by a query or dataset, so it cannot independently detect threats or trigger alerts. Using these tools for security monitoring would require building custom scheduled queries and dashboards, and even then they lack anomaly-detection logic, making them unsuitable for real-time detection.
- ✗
AWS Config and Amazon SNS
Why it's wrong here
AWS Config is a configuration management service that records and evaluates resource configuration changes against CIS-style rules, such as checking whether S3 buckets are public or have versioning enabled; it does not read S3 access logs or analyze individual API calls for malicious behavior. Amazon SNS is a message delivery service that can send notifications, but it depends on another service to supply a meaningful security event, and AWS Config does not generate findings for anomalous S3 data-plane activity. Therefore, this pairing can detect compliance drift but not real-time malicious access to objects.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.