Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security team has enabled AWS CloudTrail in all regions and is delivering logs to an S3 bucket. The team has also enabled S3 server access logging for the CloudTrail bucket. The team needs to detect any unauthorized access to the CloudTrail logs. Which combination of services should the team use to achieve near-real-time detection?

⚠ Common exam trap

Many exam-takers confuse AWS CloudTrail Insights (which analyzes management events for anomalies) with GuardDuty (which provides broader threat detection including S3 data events), leading them to choose Option A despite its lack of near-real-time S3 access detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty and Amazon CloudWatch Events

Amazon GuardDuty continuously monitors S3 data plane events, including CloudTrail log delivery and S3 server access logs, to detect suspicious API calls or unauthorized access patterns. Amazon CloudWatch Events (now part of Amazon EventBridge) can trigger near-real-time alerts when GuardDuty generates findings, enabling immediate response. This combination provides the required near-real-time detection without relying on batch analysis or configuration rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail Insights and Amazon CloudWatch

    Why it's wrong here

    AWS CloudTrail Insights is a machine-learning feature that identifies unusual API activity in management events, such as spikes in error rates or anomalous IAM actions, not malicious S3 object-level access. It does not inspect or correlate S3 data events like GetObject or PutObject for threat signatures, and Amazon CloudWatch is purely a monitoring/alerting service that has no built-in security detection engine. Together, these services cannot determine whether S3 access patterns are malicious, so they fail the real-time detection requirement.

  • ✓

    Amazon GuardDuty and Amazon CloudWatch Events

    Why this is correct

    Amazon GuardDuty is a continuous threat detection service that consumes AWS CloudTrail S3 data events, VPC flow logs, and DNS logs to identify suspicious S3 access, such as requests from unusual geographies, compromised credentials, or bucket exfiltration attempts. When a finding is generated, GuardDuty publishes it to Amazon CloudWatch Events (now part of Amazon EventBridge), enabling automated notification through SNS or invocation of Lambda for remediation. This end-to-end pipeline provides the real-time, actionable alerting required for S3 access anomalies.

  • ✗

    Amazon Athena and Amazon QuickSight

    Why it's wrong here

    Amazon Athena is an interactive SQL query engine that runs ad-hoc queries against stored S3 access logs or CloudTrail logs, which is useful for post-incident forensics but does not continuously ingest or analyze new log events as they arrive. Amazon QuickSight is a visualization/dashboard service that only displays data prepared by a query or dataset, so it cannot independently detect threats or trigger alerts. Using these tools for security monitoring would require building custom scheduled queries and dashboards, and even then they lack anomaly-detection logic, making them unsuitable for real-time detection.

  • ✗

    AWS Config and Amazon SNS

    Why it's wrong here

    AWS Config is a configuration management service that records and evaluates resource configuration changes against CIS-style rules, such as checking whether S3 buckets are public or have versioning enabled; it does not read S3 access logs or analyze individual API calls for malicious behavior. Amazon SNS is a message delivery service that can send notifications, but it depends on another service to supply a meaningful security event, and AWS Config does not generate findings for anomalous S3 data-plane activity. Therefore, this pairing can detect compliance drift but not real-time malicious access to objects.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.