Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

Network Topology
aws cloudtrail lookup-eventslookup-attributes AttributeKey=EventNamestart-time 2024-01-01T00:00:00Zend-time 2024-01-02T00:00:00ZRefer to the exhibit.```"Events": ["EventId": "example-event-id-1","EventName": "ConsoleLogin","ReadOnly": "False","Username": "user1","EventTime": "2024-01-01T10:00:00Z","CloudTrailEvent": "{\"userIdentity\":{\"type\":\"IAMUser\",\"arn\":\"arn:aws:iam::123456789012:user/user1\"},\"responseElements\":{\"ConsoleLogin\":\"Success\"}}"},"EventId": "example-event-id-2","EventTime": "2024-01-01T10:05:00Z",

Refer to the exhibit. A security engineer runs the AWS CLI command to look up console login events. The output shows two successful login events for user1 within 5 minutes. What should the engineer suspect?

⚠ Common exam trap

A common mix-up: candidates assume multiple logins are due to shared credentials or MFA misconfiguration, but the key indicator of compromise is the temporal proximity of two successful logins, which strongly suggests an attacker is using the same credentials concurrently.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user's credentials may be compromised.

Two successful console login events for the same user within 5 minutes, especially from different source IP addresses or user agents, is a strong indicator of credential compromise. An attacker who has obtained the user's password can log in while the legitimate user is also active, creating overlapping sessions. AWS CloudTrail records the `ConsoleLogin` event with details like `sourceIPAddress` and `userAgent`, which the engineer should examine to confirm whether the logins originated from different locations or devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user created a new access key.

    Why it's wrong here

    Console authentication uses the IAM user's password and optional MFA device; access keys are independent, long-term credentials for signing AWS API/CLI requests. Creating a new access key would generate a CreateAccessKey CloudTrail event and would not produce repeated ConsoleLogin events. The exhibit's pattern of sign-in events is therefore unrelated to access key creation.

  • ✓

    The user's credentials may be compromised.

    Why this is correct

    Multiple successful console sign-ins from the same IAM user in a short window, particularly from different source IP addresses or geographies, is a well-recognized indicator of credential theft. An attacker who has obtained the user's password (and possibly bypassed MFA) will often log in repeatedly to establish persistence, exfiltrate data, or escalate privileges. The correct incident-response action is to treat these events as evidence of compromise, invalidate the credentials immediately, and review CloudTrail for unauthorized actions.

  • ✗

    The user's account is being used by multiple users.

    Why it's wrong here

    While it is possible that multiple human operators are sharing the same IAM user credentials, this explanation is less likely than compromise and does not align with the typical behavioral pattern observed in the exhibit. Legitimate sharing, even if an anti-pattern, would generally show logins from a known set of IPs and at cooperative, non-overlapping times; rapid, repeated logins are more characteristic of automated tooling or an attacker cycling through sessions. The security engineer's immediate priority is to assume compromise, not to assume an internal-sharing scenario, which is also mitigated by IAM best practices of one IAM user per person or using role-based access.

  • ✗

    The user has disabled multi-factor authentication (MFA).

    Why it's wrong here

    The exhibit shows console sign-in events but does not include any information about the user's MFA configuration, which is queried via the IAM credential report or the GetMFADevice API, not through login trails. Disabling MFA would itself be an IAM change that should appear as a DeactivateMFADevice event in CloudTrail; it also would not directly cause a burst of logins. Even if MFA were absent, the observed event pattern would still point to compromised credentials rather than to the action of disabling MFA.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.