Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security team needs to detect unauthorized API calls made from a compromised IAM user. Which AWS service should be used to monitor and alert on specific API activities?

⚠ Common exam trap

Watch out — candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which logs API calls), or they assume GuardDuty's threat detection covers all API-level monitoring, but GuardDuty does not provide per-API-call logging or allow custom alerting on specific actions like `iam:CreateAccessKey`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including those from IAM users, and delivers event history for auditing. By enabling CloudTrail trails with management event logging and configuring Amazon CloudWatch alarms or EventBridge rules on specific API actions (e.g., `iam:CreateUser`, `ec2:AuthorizeSecurityGroupIngress`), the security team can detect and alert on unauthorized API activities from a compromised IAM user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the correct choice because it is the native AWS service that records API activity in your account, capturing who made the call, from which source IP, what action was invoked, and when it occurred. For unauthorized API call detection, you can enable CloudTrail across all regions, turn on data events for sensitive services like S3 or Lambda, and use CloudTrail Lake or integration with Amazon EventBridge to trigger real-time alerts on specific unauthorized actions. Unlike configuration state or network flow data, CloudTrail delivers a complete audit trail of every management and data-plane API call.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is not designed to log API calls; instead, it continuously records and evaluates the configuration state of your AWS resources, such as whether an S3 bucket is public or an EC2 instance has the correct instance type. While Config can help detect unauthorized configuration changes after the fact, it does not provide details about which principal made the API call or what exact API action was invoked, so it cannot serve as an audit log for unauthorized API activity.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a managed threat detection service that uses machine learning and integrated threat intelligence to identify suspicious behavior, such as unusual API activity, cryptocurrency mining, or compromised credentials. However, GuardDuty does not provide a comprehensive, queryable log of every API call; it only emits findings for detected threats. For proactively detecting unauthorized API calls, you need the raw API audit trail from CloudTrail, which GuardDuty itself consumes as one of its data sources.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic flowing across your VPC network interfaces, including source/destination IP addresses, ports, protocols, and packet counts. They do not log AWS API calls, which are control-plane or data-plane operations performed via the AWS API, not network-level traffic. Unauthorized API calls can be made without generating any VPC flow log entry, so this option cannot satisfy the requirement to detect such activity.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.