Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

During a security incident, a security engineer needs to capture network traffic between an EC2 instance and an attacker's IP address for forensic analysis. The engineer has already identified the attacker's IP from CloudTrail logs. Which action captures the traffic without affecting the instance?

⚠ Common exam trap

Candidates often confuse VPC Flow Logs (which only provide metadata) with full packet capture capabilities, or they assume that SSHing into the instance is acceptable despite the risk of altering the instance state during an active incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a VPC Traffic Mirroring session targeting the instance's ENI and mirror the traffic to a Network Load Balancer for capture.

VPC Traffic Mirroring captures all network traffic at the Elastic Network Interface (ENI) level without any performance impact or configuration change on the EC2 instance itself. It copies the traffic to a Network Load Balancer (NLB) or another target for capture and analysis, making it ideal for forensic investigation without disrupting the running instance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Update the network ACL to log all traffic to and from the attacker's IP.

    Why it's wrong here

    Network ACLs operate at the subnet boundary and do not have any native traffic logging capability—they are evaluated per packet but do not emit a log of the connections or payloads they permit or deny. The only way to get NACL-related logging in AWS is through CloudTrail, which logs API calls to modify the NACL, not the traffic itself. Therefore, updating a NACL to 'log' is impossible and would neither capture the attacker's IP traffic nor any forensic data.

  • ✗

    Enable VPC Flow Logs on the subnet and query logs for the attacker's IP.

    Why it's wrong here

    VPC Flow Logs record metadata about IP traffic, including source/destination IP addresses, ports, protocol, and packet/byte counts, but they never capture the content or payload of the packets. Because incident response often requires inspecting the actual data exchanged with the attacker (e.g., malware payloads, exfiltrated data), flow logs alone cannot provide the necessary forensic evidence. Additionally, flow logs are aggregated, sampled, and are not retroactive—they only start logging after the feature is enabled, so they cannot recover traffic that already occurred.

  • ✗

    SSH into the instance and run tcpdump with a filter for the attacker's IP.

    Why it's wrong here

    SSHing into a potentially compromised instance to run tcpdump is invasive: it alters system state, updates atime, adds entries to shell history, and could alert an adversary who is watching the session. More importantly, tcpdump on a compromised host cannot be trusted because the attacker may have replaced or subverted the tool, kernel modules, or libpcap. Passive packet capture via VPC Traffic Mirroring avoids these risks by operating at the hypervisor layer, ensuring the instance and its operating system are never touched.

  • ✓

    Create a VPC Traffic Mirroring session targeting the instance's ENI and mirror the traffic to a Network Load Balancer for capture.

    Why this is correct

    VPC Traffic Mirroring copies traffic from the instance's ENI to a specified target—such as a Network Load Balancer configured with a capture appliance—without installing agents or SSHing into the instance. Because the mirroring runs in the VPC data path (at the hypervisor), it is transparent to the instance and does not alert the attacker or affect system performance. This makes it the recommended approach for real-time, full-packet capture during incident response while preserving the integrity of the evidence.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.