Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

Match each AWS CloudTrail log type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Control plane operations

Resource operations like S3 object access

Unusual activity detection

Invocation of Lambda function URLs

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Management events: Records management operations performed on AWS resources, such as creating or deleting VPCs.

CloudTrail has three main log types: Management events (control plane, logged by default), Data events (data plane, optional), and Insight events (anomaly detection, optional). Common confusions include swapping management vs data definitions, or misunderstanding insight events as real-time logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Management events: Records management operations performed on AWS resources, such as creating or deleting VPCs.

    Why this is correct

    Management events record control plane operations that create, modify, or delete AWS resources, such as CreateVpc, DeleteSubnet, or attaching an IAM policy. CloudTrail logs these events by default in every region and delivers them to your configured S3 bucket. They capture the identity, source IP, and time of each API call, but they do not include the high-volume data plane activity inside a resource.

  • ✓

    Data events: Records resource operations performed on or within a resource, such as reading or writing S3 objects.

    Why this is correct

    Data events capture data plane operations performed on or within a resource, such as GetObject and PutObject on an S3 bucket, or Invoke calls on a Lambda function. Unlike management events, data events are not logged by default; you must explicitly enable them on specific resources or resource types in a trail or CloudTrail Lake event data store. Because data events can have extremely high volume, they are typically disabled by default to avoid unexpected storage costs.

  • ✓

    Insight events: Detects unusual activity in your account, such as a spike of API calls or a change in access patterns.

    Why this is correct

    Insight events are generated by CloudTrail Insights, which continuously analyzes management events against baseline patterns to detect anomalous activity, such as a sudden spike in API calls, unusual access patterns, or a write role being used unexpectedly. When an anomaly is identified, CloudTrail emits a pair of insight events marking the start and end of the anomalous window. These events do not correspond to a single API action; rather, they are derived from statistical deviations in overall management activity.

  • ✗

    Management events: Records resource operations performed on or within a resource, such as reading or writing S3 objects.

    Why it's wrong here

    This statement is incorrect because it describes data events, not management events. Management events are control plane operations like creating a VPC or deleting a subnet, not actions on or within a resource such as reading an S3 object. Data events are optional and must be explicitly enabled, whereas management events are logged by default. The description as written clearly defines data events, so it is not a valid characterization of management events.

  • ✗

    Insight events: Records all API calls made in your account in real-time.

    Why it's wrong here

    This statement is incorrect because CloudTrail is not real-time and insight events do not record every API call. CloudTrail typically delivers events up to 15 minutes after the activity occurs, and insight events are generated only after CloudTrail Insights detects unusual patterns in management events. Insight events are a curated set of anomaly notifications, not an exhaustive account-wide log. The description better fits management events or a near-real-time logging service, but it does not accurately describe insight events.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.