SCS-C02 Security Logging and Monitoring Practice Question
Which THREE actions can be performed using AWS CloudTrail to enhance security monitoring?
⚠ Common exam trap
Watch out — candidates often confuse CloudTrail's scope with OS-level or network-level monitoring, mistakenly thinking it can capture SSH logins or network traffic, when in fact it only records AWS API calls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detect unauthorized API calls by analyzing CloudTrail logs.
AWS CloudTrail records API activity in your AWS account, including calls to IAM, S3, and other services. By analyzing CloudTrail logs, you can detect unauthorized API calls (Option B) because every API call is logged with details such as the identity, source IP, and timestamp, enabling security monitoring and alerting on suspicious actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Monitor SSH login attempts to EC2 instances.
Why it's wrong here
CloudTrail is an API auditing service that captures control-plane API calls made to AWS, so it does not record operating-system-level authentication events such as SSH login attempts. SSH logins occur inside an EC2 instance's guest OS and are therefore invisible to CloudTrail. To monitor SSH access, you would need to enable VPC Flow Logs for network-level connection tracking, deploy an agent to forward /var/log/auth.log or similar, or use AWS Systems Manager Session Manager for session-level logging.
- ✓
Detect unauthorized API calls by analyzing CloudTrail logs.
Why this is correct
CloudTrail delivers a record of every AWS API call, capturing the requesting principal, source IP, user agent, and request parameters, regardless of whether the call succeeded or was denied. Security teams can analyze these logs to detect unauthorized attempts, such as AccessDenied errors, calls from unexpected identities or regions, or anomalous API patterns. This detective capability is often combined with Amazon GuardDuty or Athena queries to surface suspicious activity that would otherwise go unnoticed.
- ✓
Monitor changes to S3 bucket policies.
Why this is correct
S3 bucket policies are managed through the S3 control plane, so every attempt to set, modify, or remove a bucket policy triggers a PutBucketPolicy or DeleteBucketPolicy API call that CloudTrail records along with the caller's identity and the new policy document. You can then create an EventBridge rule or CloudWatch alarm on these events to alert on policy changes, or use CloudTrail Lake to query for such modifications. This makes CloudTrail a crucial detective control for protecting S3 data from unintended public exposure.
- ✗
Capture all network traffic to and from EC2 instances.
Why it's wrong here
CloudTrail is not a network capture tool; it records API activity and includes the source IP address of each request, but it does not ingest packets, flows, or payloads traveling to and from an EC2 instance. To capture network traffic metadata, you must enable VPC Flow Logs, which log IP traffic going to and from ENIs within a VPC, or use traffic mirroring for full packet inspection. CloudTrail's source IP information is only for authentication and API auditing, not for analyzing network conversation data.
- ✓
Track changes to IAM user permissions.
Why this is correct
CloudTrail records all IAM management calls, including CreatePolicy, AttachRolePolicy, PutUserPolicy, and AddUserToGroup, which means you can track exactly when and how an IAM user's permissions are modified and by whom. This visibility is essential for detecting privilege escalation or unauthorized changes to least-privilege configurations. You can build alerts or use CloudTrail's integration with EventBridge to respond immediately to changes that broaden access.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.