SCS-C02 Management and Security Governance Practice Question
Which TWO actions are effective for detecting and responding to unauthorized access in an AWS environment? (Choose two.)
⚠ Common exam trap
Many candidates confuse detection services (like GuardDuty and CloudTrail) with automated remediation services (like AWS WAF or Lambda-based blocking), leading them to incorrectly select Security Hub as a blocking mechanism or IAM Access Analyzer as a real-time detection tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS CloudTrail and monitor logs for suspicious activity.
AWS CloudTrail records all API activity in your AWS environment, including management and data plane events. By enabling CloudTrail and monitoring its logs for suspicious activity (e.g., unusual API calls, failed authentication attempts, or access from unexpected IP addresses), you can detect unauthorized access. This is a foundational detective control that provides the audit trail necessary for incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable AWS CloudTrail and monitor logs for suspicious activity.
Why this is correct
CloudTrail records all API activity in your account—who made the call, from which IP, when, and with what outcome—enabling you to audit for suspicious behavior like new keys or unusual regions. But simply enabling CloudTrail is not enough; you must actively monitor the logs via CloudWatch Logs, Athena, or a SIEM. This is a detective control, not a preventive one, so it requires continual human or automated review to catch anomalies.
- ✓
Deploy Amazon GuardDuty to analyze CloudTrail logs and VPC Flow Logs for threats.
Why this is correct
GuardDuty takes the raw data from CloudTrail, VPC Flow Logs, and DNS logs and applies machine learning models and threat intelligence feeds to identify findings like crypto-mining, compromised credentials, or command-and-control traffic. It reduces the manual effort of poring over logs by prioritizing unusual patterns and correlating events across sources. However, GuardDuty only produces findings; responding still requires you to integrate with services like EventBridge and Lambda. This makes it an intelligent detection service rather than a raw logging mechanism.
- ✗
Use AWS Security Hub to automatically block suspicious IP addresses.
Why it's wrong here
Security Hub aggregates security findings from multiple AWS services and provides a consolidated view of your security posture, but it has no native capability to block suspicious IP addresses. To actually block an IP, you would need to deploy a resource like AWS WAF, network ACL, or security group rules, and enforce those changes via custom automation (e.g., EventBridge triggering a Lambda function). Security Hub cannot be used as a direct enforcement point, so the action as stated is technically unsupported.
- ✗
Enable VPC Flow Logs to capture all network traffic.
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic interacting with network interfaces, including source and destination IPs, ports, protocols, and accept/reject status, but they do not capture the actual content or payload of the traffic. While this information is valuable for network diagnostics and analyzing connection attempts, Flow Logs are purely a logging mechanism—they do not perform analysis or detect unauthorized access. The claim that they capture 'all network traffic' is misleading because they omit the data itself and only reflect flow summaries.
- ✗
Enable IAM Access Analyzer to detect unauthorized access attempts.
Why it's wrong here
IAM Access Analyzer continuously inspects resource-based policies, such as S3 bucket policies and KMS key policies, to identify resources shared with external accounts or principals. It is a preventive and proactive tool intended to catch potential permissions issues before they are exploited, not a detective tool that identifies unauthorized access attempts or ongoing intrusions. Therefore, using Access Analyzer in the context of detecting active security events is a mismatch of its actual function.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.