Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security team is designing a logging solution for a multi-account AWS environment using AWS Organizations. They need to collect CloudTrail logs, VPC Flow Logs, and DNS logs from all accounts. Which TWO services can be used to centralize this logging?

⚠ Common exam trap

Candidates may mistakenly choose CloudTrail (Organization Trail) because it centralizes CloudTrail logs, but it does not apply to the other log types. The correct central aggregation services are CloudWatch Logs and S3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Logs

Amazon CloudWatch Logs (A) is correct because it can serve as a centralized log repository where log groups from multiple accounts stream CloudTrail, VPC Flow Logs, and Route 53 DNS query logs via subscription filters and cross-account log sharing, enabling a single security account to aggregate and query all log data. Amazon S3 (E) is correct because it is the standard centralized destination for CloudTrail log file delivery (including organization trails), VPC Flow Logs (delivered to S3 buckets), and Route 53 DNS query logs, with cross-account bucket policies and AWS Organizations allowing all member accounts to write into a central logging bucket. AWS CloudTrail (Organization Trail) (B) is not correct here because it only captures CloudTrail API activity across accounts, not VPC Flow Logs or DNS logs, so it cannot centralize all three log types. AWS Config (C) is not correct because it records resource configuration changes and compliance state, not CloudTrail, VPC Flow Log, or DNS log data. Amazon GuardDuty (D) is not correct because it is a threat-detection service that consumes logs to generate findings, not a service for centralizing and storing the raw logs themselves.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    Amazon CloudWatch Logs is incorrect because it primarily serves as a destination for log streams within individual AWS accounts, providing real-time monitoring and analysis capabilities. While CloudTrail, VPC Flow Logs, and DNS logs can be directed to CloudWatch Logs, it lacks a native, managed mechanism to centrally *collect and aggregate* these log types *from multiple accounts* within an AWS Organizations structure into a single logging account. It is tempting because CloudWatch Logs is a core log management service, ideal for operational visibility, metric extraction, and alerting on logs *per account*, or for smaller-scale log storage.

  • ✗

    AWS CloudTrail (Organization Trail)

    Why it's wrong here

    AWS CloudTrail Organization Trail is the correct answer because it automatically creates a single trail that collects management events from every account and AWS Region within an AWS Organization. The trail delivers a centralized, read-only log of API activity to one designated S3 bucket in the management or delegated administrator account. This provides native, organization-wide aggregation of management event logs, directly addressing the requirement to aggregate logs from multiple accounts.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration state transitions and evaluates those states against compliance rules, producing configuration history and compliance snapshots. It does not ingest or store operational logs such as VPC Flow Logs, DNS query logs, or API activity; instead, its outputs are configuration items and rule evaluations. Therefore, AWS Config is a governance and compliance tool, not a multi-account log aggregation solution.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that consumes VPC Flow Logs, DNS logs, and CloudTrail events to produce security findings. Its output is a stream of alerts and findings, not raw log data. It cannot serve as a central logging repository because it does not ingest or store the log files themselves, nor does it aggregate logs across accounts natively.

  • ✓

    Amazon S3

    Why this is correct

    Amazon S3 is correct because it can serve as a central, durable data lake for log aggregation. VPC Flow Logs, DNS query logs from Route 53 Resolver, and CloudTrail (via Organization Trail) can all be delivered to an S3 bucket, and cross-account delivery can be achieved through resource-based bucket policies. S3 enables scalable, cost-effective storage of logs from multiple accounts in one central repository, making it a key component of the logging solution.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.