Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

Which THREE services can be used to detect and alert on suspicious API activity across an AWS organization? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse AWS Config's compliance monitoring (e.g., checking if CloudTrail is enabled) with actual threat detection, but Config does not analyze API calls for suspicious patterns—it only checks configuration state against rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including suspicious API activity. It uses machine learning, anomaly detection, and integrated threat intelligence to analyze AWS CloudTrail management events, VPC Flow Logs, and DNS logs across an AWS organization, and can trigger alerts via Amazon EventBridge or Security Hub.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is an automated security assessment service that scans Amazon EC2 instances, container images, and Lambda functions for software vulnerabilities, unintended network exposure, and deviations from security best practices. It does not ingest CloudTrail event logs or monitor real-time user/API behavior, so it cannot detect suspicious activity such as compromised credentials or anomalous API calls. Its focus is on identifying configuration weaknesses and patch gaps, not on continuous threat detection and alerting.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is a continuous threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to analyze AWS CloudTrail management events, VPC Flow Logs, and DNS query logs. It identifies suspicious API calls, potential credential compromise, and malicious network traffic, and generates detailed findings that can be sent to CloudWatch Events to trigger automated notifications or responses. This directly enables detection and alerting on suspicious activity in near real-time.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a configuration recording and compliance service that tracks resource configurations and configuration changes over time, allowing you to evaluate them against desired baseline rules. It does not analyze API call patterns, user behavior, or network traffic, so it cannot identify malicious or unauthorized activity. While Config can alert on non-compliant resource settings, it is not designed to detect security threats or suspicious events.

  • ✓

    AWS Security Hub

    Why this is correct

    AWS Security Hub is a cloud security posture management service that aggregates and correlates findings from AWS services such as GuardDuty, Inspector, Macie, and third-party security tools into a single dashboard. It can detect suspicious activity by running continuous security checks and correlating findings, then generate alerts via CloudWatch Events or custom actions for automated remediation. Thus it serves as a key service for detecting and alerting on potential threats across the account.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail records all API activity in an AWS account, capturing details like the caller identity, source IP, and event time for every management event. By enabling CloudTrail to send logs to CloudWatch Logs, you can define metric filters to trigger CloudWatch Alarms on specific suspicious patterns, such as IAM policy changes or failed console logins. This makes CloudTrail a foundational service for auditing and historically detecting suspicious behavior, though it requires additional configuration to generate alerts.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.