SCS-C02 Infrastructure Security Practice Question
A security team needs to audit all changes to security group rules across multiple AWS accounts in an organization. Which combination of services should be used to meet this requirement?
⚠ Common exam trap
SCS-C02 often tests the misconception that AWS Config alone can provide a full audit trail of who made changes, when in fact CloudTrail is required to capture the API-level identity and request details.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config and AWS CloudTrail.
AWS Config continuously records changes to resource configurations, including security group rules, and can evaluate them against desired configurations. AWS CloudTrail captures API activity, so it logs the actual API calls that modify security groups (e.g., AuthorizeSecurityGroupIngress). Together, Config provides the configuration change history and CloudTrail provides the who, what, when, and from where for each change. This combination is the standard AWS approach for auditing security group modifications across multiple accounts, especially when centralized via AWS Organizations and a delegated administrator.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch Logs and AWS CloudTrail.
Why it's wrong here
This pair includes AWS CloudTrail, which does capture API calls that alter security groups, but Amazon CloudWatch Logs is designed for application log storage and analysis, not for maintaining a resource configuration history. Without AWS Config, there is no record of the resulting security group state changes, compliance evaluation, or configuration snapshots needed to audit all changes. Thus it fails to provide a complete audit trail of configuration modifications.
- ✗
Amazon GuardDuty and AWS Security Hub.
Why it's wrong here
Amazon GuardDuty and Security Hub are security monitoring and detection services: GuardDuty analyzes VPC Flow Logs, DNS, and CloudTrail data for threat behavior, while Security Hub aggregates findings and runs compliance checks. Neither service records the exact chronological changes to a security group's inbound/outbound rules, and their findings are ephemeral alerts rather than an authoritative audit history. For auditing configuration changes, you need services that capture resource state and API activity, not threat indicators.
- ✗
AWS Trusted Advisor and AWS Config.
Why it's wrong here
AWS Trusted Advisor provides only high-level checks across cost, performance, security, and fault tolerance, but it does not log each modification or identify who made the change. While AWS Config can determine the current security group configuration, Trusted Advisor itself has no event history or configuration snapshot capability, so this pairing cannot reconstruct the full audit trail. The missing AWS CloudTrail element is essential to tie each Config-detected change to a specific API call and the associated user.
- ✓
AWS Config and AWS CloudTrail.
Why this is correct
AWS Config continuously records the configuration state of security groups, including each ingress and egress rule change, and can deliver configuration-history timelines and compliance snapshots. AWS CloudTrail captures the API actions that initiate those changes, logging the principal, user agent, and request parameters for every management event. Together they provide both the 'what' (configuration state via Config) and the 'who/when/how' (API activity via CloudTrail), enabling a complete audit trail of security group changes. For example, when a rule is removed, Config shows the new state while CloudTrail reveals the identity of the caller.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.