SCS-C02 Threat Detection and Incident Response Practice Question
During an incident investigation, a security analyst finds that an IAM user 'JohnDoe' has been using an access key that was last rotated over 2 years ago. The analyst needs to determine if this key has been compromised. Which approach provides the MOST definitive evidence?
⚠ Common exam trap
It's easy for candidates to assume S3 access logs (Option A) are the definitive source for detecting compromise, but they miss that CloudTrail provides a complete audit trail of all API calls, including those that don't involve S3 data access, making it the superior choice for identifying anomalous behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudTrail LookupEvents to find API calls made by the key, focusing on unusual IP addresses or times
AWS CloudTrail LookupEvents allows you to filter API calls by user identity (such as the access key ID) and examine attributes like source IP address, user agent, and timestamp. Unusual IP addresses or times of day are strong indicators of compromise, as they suggest the key is being used from locations or at hours inconsistent with the legitimate user's behavior. This provides the most definitive evidence because it directly correlates the key's usage with anomalous patterns, rather than relying on indirect indicators like data downloads or permission changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the S3 access logs to see if the key was used to download sensitive data
Why it's wrong here
S3 server access logs only capture object-level operations against a specific bucket (e.g., GetObject, PutObject, ListObjects) and are not a global API activity log. They may include the access key ID in the 'requester' field, but they cannot reveal the full spectrum of API calls that a compromised key could make across services, nor do they cover actions outside S3. Therefore, they are insufficient to determine whether the key was used to download sensitive data from any service other than S3, and even for S3 they are best-effort and often delayed.
- ✓
Use AWS CloudTrail LookupEvents to find API calls made by the key, focusing on unusual IP addresses or times
Why this is correct
CloudTrail LookupEvents is the correct tool because it queries the CloudTrail event history for actual API calls made by an access key, including action name, source IP address, user agent, and timestamp. You can specify the AccessKeyId in the lookup filter to see every call attributed to that key, then correlate those calls with unusual IP addresses or times to spot anomalous behavior. This gives the security analyst direct evidence of what the compromised key did across AWS services, which is exactly the goal of the investigation.
- ✗
Review the IAM password policy to see if the key was created before the current policy
Why it's wrong here
The IAM password policy governs user password complexity, minimum length, expiration, and reuse rules—it has no bearing on access keys or their validity. Existing long-term access keys are not retroactively affected when a password policy is changed; they remain active until explicitly rotated, deleted, or their parent IAM user is disabled. Reviewing it would tell you nothing about whether the access key was used or misused, so this is a distractor focused on the wrong credential type.
- ✗
Use AWS Config to see if the key's permissions have changed
Why it's wrong here
AWS Config records configuration changes to AWS resources—such as changes to IAM policy attachments—so it might show if a key's effective permissions were modified. However, it does not capture API call activity, and its scope is resource compliance and configuration drift, not user-action auditing. It cannot tell you which operations the access key performed, when it performed them, or from which IP address, so it cannot support a breach investigation. To find out what the key actually did, you need an activity log like CloudTrail, not a configuration history.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.