SCS-C02 Security Logging and Monitoring Practice Question
A security team wants to detect and alert on potential security threats such as compromised instances or malicious activity within their AWS environment. Which TWO AWS services should be used together to provide comprehensive threat detection?
⚠ Common exam trap
Watch out — candidates often confuse logging services (CloudTrail, Config) or vulnerability scanners (Inspector) with active threat detection, but GuardDuty and Security Hub are the only pair that provide continuous, intelligent threat monitoring and centralized alerting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Hub
Amazon GuardDuty (E) is correct because it is the AWS managed threat detection service that continuously monitors VPC Flow Logs, DNS logs, and CloudTrail management/event logs using machine learning and threat intelligence feeds to identify compromised instances, reconnaissance, and malicious activity. AWS Security Hub (A) is correct because it aggregates and prioritizes findings from GuardDuty and other services into a single dashboard, enabling centralized alerting and automated response workflows for comprehensive threat visibility. Together, GuardDuty provides the detection engine while Security Hub provides aggregation and alerting. AWS CloudTrail (B) only records API activity for auditing and does not itself detect or alert on threats. Amazon Inspector (C) is a vulnerability management service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure, not runtime threat detection. AWS Config (D) evaluates resource configuration compliance against rules and does not perform threat detection or alerting on malicious behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Security Hub
Why this is correct
Security Hub aggregates and prioritises findings from GuardDuty, which performs the actual threat detection for compromised instances and malicious activity. Together they satisfy the requirement for comprehensive detection plus centralised alerting across the AWS environment.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records API activity for audit and compliance; it does not analyse instance behaviour or network traffic for malicious patterns, so it cannot deliver the threat detection required. CloudTrail is the right choice for API-level auditing, whereas GuardDuty performs the actual threat identification.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector performs vulnerability scanning of EC2 instances, container images and Lambda functions; it does not detect active compromise or malicious behaviour. It is tempting because it is a genuine security service, and would be correct for continuous CVE assessment against a defined benchmark, but the scenario requires runtime threat detection, which GuardDuty provides.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configuration changes and evaluates them against rules; it detects drift and non-compliance, not compromised instances or malicious activity. It is tempting because it is a security-adjacent service, and would be correct for tracking configuration history or enforcing compliance, but the scenario needs behavioural threat detection, which GuardDuty delivers.
- ✓
Amazon GuardDuty
Why this is correct
GuardDuty continuously analyses CloudTrail, VPC Flow Logs and DNS logs with threat intelligence and machine learning to surface compromised instances and malicious activity. It provides the detection layer that pairs with an alerting service for comprehensive threat visibility.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.