Courseiva
Security Logging and MonitoringmediumMultiple SelectObjective-mapped

SCS-C02 Security Logging and Monitoring Practice Question

A security team wants to detect and alert on potential security threats such as compromised instances or malicious activity within their AWS environment. Which TWO AWS services should be used together to provide comprehensive threat detection?

⚠ Common exam trap

Watch out — candidates often confuse logging services (CloudTrail, Config) or vulnerability scanners (Inspector) with active threat detection, but GuardDuty and Security Hub are the only pair that provide continuous, intelligent threat monitoring and centralized alerting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Security Hub

Amazon GuardDuty (Option E) is a threat detection service that continuously monitors for malicious activity and unauthorized behavior using machine learning, anomaly detection, and integrated threat intelligence feeds. AWS Security Hub (Option A) aggregates findings from GuardDuty and other services, applies automated compliance checks, and enables centralized alerting and response. Together, they provide comprehensive threat detection by combining GuardDuty's raw threat detection with Security Hub's aggregation and orchestration capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Security Hub

    Why this is correct

    Aggregates and prioritizes security findings.

  • AWS CloudTrail

    Why it's wrong here

    CloudTrail logs API calls, not threat detection.

  • Amazon Inspector

    Why it's wrong here

    Inspector is for vulnerability assessments, not ongoing threat detection.

  • AWS Config

    Why it's wrong here

    Config tracks configuration changes, not threats.

  • Amazon GuardDuty

    Why this is correct

    Provides threat detection using machine learning.

About these practice questions

One of 376 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.