Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

During a security incident, a security engineer needs to verify whether an EC2 instance's security group allowed inbound SSH from a specific IP address at the time of the incident. Which AWS service or feature should the engineer use to obtain this historical information?

⚠ Common exam trap

Many candidates confuse VPC Flow Logs (which show traffic) with security group configuration history, but Flow Logs only show whether traffic was permitted or denied based on the rules at that time, not the rules themselves.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config configuration history.

AWS Config configuration history records changes to security group rules, including the addition or removal of inbound SSH allow rules. By querying the configuration history for the specific security group, the engineer can determine the exact state of the rules at the time of the incident, including whether a specific IP address was allowed. This is the only service that provides a historical record of security group rule configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudTrail event history.

    Why it's wrong here

    Amazon CloudTrail event history records the API actions performed on a security group, such as AuthorizeSecurityGroupIngress or RevokeSecurityGroupEgress. However, it only shows that an action occurred and by whom, not the resulting set of rules in effect at the moment of the incident. You would have to correlate and replay all events to reconstruct the state, which is error-prone and not a supported point-in-time view.

  • ✗

    AWS Systems Manager Inventory.

    Why it's wrong here

    AWS Systems Manager Inventory is an agent-based feature that collects information from your EC2 instances, such as installed software, OS updates, and network configuration. It does not have any visibility into VPC-level resources like security group rules, which are managed by the EC2 and VPC services. Therefore, it cannot provide evidence of the security group state needed for forensic analysis.

  • ✗

    VPC Flow Logs.

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic entering or leaving a network interface, including source/destination addresses, ports, and whether the traffic was permitted or denied. They do not contain the security group rule definitions themselves; they only reflect the outcome of those rules. Thus, flow logs can help you understand what traffic occurred, but they cannot tell you which specific rule allowed or denied a particular packet.

  • ✓

    AWS Config configuration history.

    Why this is correct

    AWS Config configuration history is the correct choice because it records the complete configuration of supported AWS resources, including security groups, whenever a change occurs. Each configuration item is timestamped, so you can retrieve the exact set of security group rules at any point in time, including during the incident. This provides a reliable, auditable point-in-time state without needing to reconstruct it from API calls or traffic logs.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.