Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

Which THREE AWS services can be used to detect potentially compromised EC2 instances? (Choose 3.)

⚠ Common exam trap

Many exam-takers confuse AWS WAF (a web-layer filter) or AWS Shield (a DDoS mitigator) with detective services, when the question specifically asks for services that *detect* compromised instances—not prevent attacks or filter traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Flow Logs

VPC Flow Logs (B) capture IP traffic metadata for ENIs, so you can analyze accepted/rejected flows for signs of compromise such as beaconing to known-bad IPs or unusual outbound traffic. Amazon GuardDuty (D) is a managed threat-detection service that continuously analyzes VPC Flow Logs, CloudTrail events, and DNS logs to identify compromised instances via findings like cryptocurrency mining or communication with malicious hosts. Amazon Inspector (E) scans EC2 instances for software vulnerabilities and unintended network exposure, which helps detect an instance that could be or has been compromised through an exploitable weakness. AWS WAF (A) is a Layer 7 web application firewall that filters HTTP(S) requests to CloudFront, ALB, or API Gateway, not an EC2 compromise-detection service. AWS Shield (C) provides DDoS protection at the network/transport layer and does not detect compromised EC2 instances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF is a web application firewall that protects HTTP/HTTPS applications via ALB, CloudFront, or API Gateway, filtering malicious web requests. It operates at Layer 7 and cannot inspect operating system or network-level activity on EC2 instances, so it would not detect a compromised instance itself.

  • ✓

    VPC Flow Logs

    Why this is correct

    VPC Flow Logs record source/destination IPs, ports, and protocol for all traffic in a VPC. Anomalies such as outbound calls to known threat-intel IPs, repeated failed connection attempts, or large data transfers can signal a compromised EC2 instance. However, Flow Logs are raw metadata requiring additional analytics (e.g., Athena queries) to surface threats.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield offers always-on detection and mitigation of DDoS attacks, such as UDP floods or SYN floods, at the network/transport layer. It does not evaluate host security or user behavior, so it cannot detect the lateral movement, credential abuse, or malware that indicate an instance compromise.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty continuously analyzes VPC Flow Logs, CloudTrail management and S3 data events, and DNS query logs using threat intelligence and machine learning. It generates findings for suspicious behaviors like cryptocurrency mining, brute force attempts, or anomalous outbound traffic, making it a direct compromise-detection service.

  • ✓

    Amazon Inspector

    Why this is correct

    Amazon Inspector is a vulnerability management service that scans EC2 instances for software vulnerabilities, unintended network exposure, and security best-practice deviations. It helps identify weaknesses that an attacker could exploit, but it does not detect live attacks or ongoing malicious activity; it assesses the risk of future compromise.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.