Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

An organization wants to detect and alert on the use of root user credentials in their AWS accounts. They have multiple accounts managed via AWS Organizations. What is the most efficient way to centralize this monitoring?

⚠ Common exam trap

Watch out — candidates often assume CloudTrail or AWS Config are sufficient for monitoring root user usage, but they overlook GuardDuty's purpose-built, centralized detection capability for security events like root credential usage across multi-account environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Amazon GuardDuty in the management account and use the delegated administrator feature.

Amazon GuardDuty, when enabled in the management account with a delegated administrator, can centrally monitor and detect suspicious activity—including root user credential usage—across all member accounts in AWS Organizations. This approach eliminates the need to configure per-account monitoring and provides a single pane of glass for security alerts, making it the most efficient centralized solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an AWS CloudTrail trail in each account and aggregate logs to a central S3 bucket.

    Why it's wrong here

    Setting up individual CloudTrail trails per account and shipping logs to a central S3 bucket only aggregates raw audit logs; it doesn't automatically inspect them for root user activity. To alert, you'd need to build separate infrastructure such as CloudWatch Logs metric filters, Athena queries, or a Lambda function to parse the logs and trigger notifications in each account. This approach requires manual setup and maintenance in every account, introducing operational overhead and configuration drift, whereas the requirement calls for centralized detection and alerting.

  • ✗

    Use IAM Access Analyzer to find resources shared with external entities.

    Why it's wrong here

    IAM Access Analyzer is designed to identify resources such as S3 buckets, KMS keys, or IAM roles that are shared with external principals via resource-based policies. It generates findings for unwanted external access, but it does not monitor or assess API-call behavior, authentication events, or the use of root user credentials. Root activity is an identity-centric event recorded in CloudTrail, not a resource-external-sharing condition, so this service cannot satisfy the detection requirement.

  • ✗

    Use AWS Config rules to detect root user usage in each account.

    Why it's wrong here

    AWS Config rules are per-account and focus on evaluating the compliance of resource configurations, not on analyzing CloudTrail API activity to detect unauthorized root usage. While you could write a custom AWS Config rule backed by a Lambda function to query recent root logins, you'd have to deploy it in every account and it would not provide a consolidated view or native alerting across the organization. Config also lacks the anomaly-detection and threat-intelligence capabilities that GuardDuty uses to flag suspicious root activity.

  • ✓

    Enable Amazon GuardDuty in the management account and use the delegated administrator feature.

    Why this is correct

    Enabling GuardDuty in the management account and designating a delegated administrator lets one account manage GuardDuty for all member accounts in the organization, aggregating findings centrally. GuardDuty uses integrated threat intelligence and anomaly detection to analyze CloudTrail management events, VPC flow logs, and DNS logs, generating a specific finding type when root user credentials are used anomalously, such as 'UnauthorizedAccess:IAMUser/RootCredentialUsage'. This provides cross-account visibility and built-in detection without needing to build custom log-analysis pipelines in each account.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.