SCS-C02 Security Logging and Monitoring Practice Question
A security team needs to monitor for unauthorized API calls in their AWS account. Which TWO services can provide real-time alerts for such events?
⚠ Common exam trap
Test-takers frequently confuse CloudWatch Logs Insights (a query tool) with real-time alerting, or they mistakenly think VPC Flow Logs can monitor API calls because they capture all traffic, but they only capture network flows, not application-level API events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail with Amazon CloudWatch Events
B is correct because AWS CloudTrail logs all API calls, and by integrating CloudTrail with Amazon CloudWatch Events (now Amazon EventBridge), you can create event rules that trigger real-time alerts (e.g., via SNS or Lambda) for unauthorized API calls. This combination provides the necessary logging and immediate notification capability for security monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch Logs Insights
Why it's wrong here
CloudWatch Logs Insights is an interactive query engine for searching and analyzing log data, but it is not a real-time alerting service. Even though CloudTrail logs can be delivered to CloudWatch Logs and then queried, you must actively run queries to find unauthorized API calls, and the results are only as current as the log ingestion delay. It lacks the ability to evaluate events continuously or trigger immediate remediation, making it unsuitable for proactive monitoring. For near-real-time notification on API activity, you would pair CloudTrail with CloudWatch Events or EventBridge, which evaluate events as they occur.
- ✓
AWS CloudTrail with Amazon CloudWatch Events
Why this is correct
AWS CloudTrail captures the complete audit trail of API calls made to your account, including the identity, time, source IP, and request parameters. By integrating CloudTrail with Amazon CloudWatch Events, you can create rules that match specific API events—such as unauthorized or denied actions—and trigger immediate alerts via SNS, Lambda, or other targets in real time. CloudTrail delivers each API event as a JSON object, and CloudWatch Events helps filter those objects by fields like `errorCode` or `userIdentity` to detect suspicious activity. This combination is the recommended native mechanism for monitoring and reacting to unauthorized API calls.
- ✗
Amazon VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about network traffic at the elastic network interface level—such as source/destination IP, ports, protocol, and packets—but they do not record application-level API calls made via the AWS management console, SDK, or CLI. Because they only reflect IP-level connections, they cannot show whether an API call succeeded, who made it, or which AWS service or action was invoked. While flow logs can help identify unusual network patterns, they are ineffective for detecting unauthorized API calls like a user deleting an S3 bucket or changing an IAM policy. A tool that parses CloudTrail events is necessary for API-level monitoring.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service that evaluates your resource configurations against desired policies and tracks configuration changes over time—it does not monitor API actions. For example, Config can detect that a security group rule was added or that an S3 bucket became public, but it does not tell you which API call made that change or whether the call itself was unauthorized. It also cannot react to an API call in real time or alert on the action alone; it only records the resulting configuration state after the change. To identify unauthorized API calls, you need CloudTrail for the call-event stream, not configuration history.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty is a threat detection service that continuously analyzes multiple data sources, including AWS CloudTrail event logs, VPC Flow Logs, and DNS query logs, to identify malicious or unauthorized activity. It uses machine learning and anomaly detection to flag unusual API patterns, such as a user disabling MFA, launching instances in an unusual region, or performing reconnaissance activities. When GuardDuty detects such behavior, it generates a finding that can be sent to Amazon CloudWatch Events (or EventBridge) in real time, enabling immediate response. Unlike a simple CloudTrail-to-Events rule, GuardDuty provides context and severity scores for threats, making it a strong complementary option—but it may rely on known threat or anomaly models, while CloudTrail + CloudWatch Events lets you define explicit custom rules for specific unauthorized API calls.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.