Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A startup uses a single AWS account for development. The security engineer wants to detect if any EC2 instances have been compromised and are performing reconnaissance by probing open ports on other internal instances. The engineer has enabled VPC Flow Logs for all subnets. What is the most cost-effective way to detect this behavior?

⚠ Common exam trap

Many exam-takers assume querying VPC Flow Logs directly with CloudWatch Logs Insights is the most cost-effective approach, but they overlook the operational cost and lack of automation, while GuardDuty provides automated, managed detection with no manual query overhead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Amazon GuardDuty and review the findings.

Amazon GuardDuty is a managed threat detection service that uses machine learning and integrated threat intelligence to analyze VPC Flow Logs, DNS logs, and other data sources. It can automatically detect reconnaissance behavior such as port probing or port scanning from compromised EC2 instances without requiring any additional infrastructure or manual query setup. This makes it the most cost-effective solution because it operates on a pay-per-volume basis and eliminates the need for custom log analysis or per-instance agents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Amazon GuardDuty and review the findings.

    Why this is correct

    Amazon GuardDuty is a managed threat detection service that continuously analyzes AWS account activity from VPC Flow Logs, DNS logs, CloudTrail management events, and S3 data events. It uses threat intelligence feeds and machine learning to automatically identify reconnaissance behavior such as port scans, SSH brute-force attempts, or unusual API calls from a suspicious IP range. Enabling GuardDuty and reviewing its severity-ranked findings gives a startup immediate, operational visibility into the attack without deploying agents or writing detection queries, and the findings can be integrated with AWS Security Hub or EventBridge for automated response.

  • ✗

    Install a third-party intrusion detection system on each EC2 instance.

    Why it's wrong here

    Deploying a third-party intrusion detection system on every EC2 instance is operationally heavy, expensive, and incomplete. Host-based agents must be installed, licensed, patched, and managed on each instance, and they inspect only traffic that reaches the host's network stack—they cannot see VPC-level scanning against unused IP addresses, DNS-layer threats, or CloudTrail API reconnaissance. In a single-account development environment, this approach adds significant cost and complexity while leaving the AWS control plane and network perimeter unmonitored, whereas GuardDuty provides account-wide coverage with no agents required.

  • ✗

    Use Amazon CloudWatch Logs Insights to query VPC Flow Logs for rejected traffic patterns.

    Why it's wrong here

    Using CloudWatch Logs Insights to query VPC Flow Logs for rejected traffic is a manual, reactive approach that requires an analyst to know exact query syntax and which patterns constitute an attack. Flow Logs contain only IP traffic metadata, not DNS queries, CloudTrail events, or threat-intelligence context, so simply looking for rejected packets will miss reconnaissance techniques where the attacker accepts a connection and performs a banner grab or sends a low-volume, distributed scan. This method also produces no automated alerts unless you separately build metric filters and alarms, making it slow and unscalable for a development account that needs prompt detection, whereas GuardDuty automatically analyzes the same flow logs plus additional sources and generates findings.

  • ✗

    Use AWS Config rules to check for security group changes.

    Why it's wrong here

    AWS Config rules are designed to evaluate resource configuration compliance, not to detect real-time network or account behavior. A Config rule could alert you when a security group is modified or when it contains an overly permissive ingress rule, but it cannot observe the actual attack traffic—for example, a host attempting to connect to many ports or a series of failed SSH logins does not change any configuration. Checking for security group changes might reveal a misconfiguration that enabled an attack, but it provides no signal about ongoing reconnaissance, which is the activity the startup is seeing. GuardDuty, by contrast, monitors the observed activity itself, making it the appropriate service for this scenario.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.