SCS-C02 Security Logging and Monitoring Practice Question
Which TWO AWS services can be used to centrally collect and analyze logs from multiple AWS accounts? (Select TWO.)
⚠ Common exam trap
The trap here is that candidates often mistake AWS Config for a log collection service because it records configuration changes, but it does not aggregate or analyze logs from multiple accounts; it only provides per-account configuration history and compliance rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Athena (to query logs in S3)
Amazon S3 can serve as a centralized log repository by aggregating logs from multiple AWS accounts using cross-account S3 bucket policies. Amazon Athena can then query those logs directly in S3 using standard SQL, enabling centralized analysis without moving data. Together, they provide a scalable, serverless solution for multi-account log collection and analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration tracking service, not a log aggregation or analysis service. It continuously records AWS resource configuration changes and evaluates them against desired policies, delivering configuration history and compliance snapshots. While Config can deliver configuration items to an S3 bucket, it does not centrally collect operational logs such as CloudTrail, VPC Flow Logs, or application logs, nor does it provide query capability over those logs.
- ✓
Amazon Athena (to query logs in S3)
Why this is correct
Amazon Athena is an interactive serverless query service that runs standard SQL directly against data stored in Amazon S3. After logs from multiple accounts are centrally delivered to an S3 bucket, Athena can query those logs (e.g., CloudTrail, VPC Flow Logs, ALB logs) without loading them into a database or managing infrastructure. It complements S3 as the storage layer by providing the analysis capability needed to search and correlate log data, making it a correct answer for centrally collecting and analyzing logs.
- ✓
Amazon S3 (as a central log repository)
Why this is correct
Amazon S3 serves as a durable, scalable, and cost-effective central repository for log data aggregated from multiple AWS accounts and services. Services like CloudTrail, VPC Flow Logs, and AWS Config can all be configured to deliver logs to a centralized S3 bucket, enabling a single source of truth for auditing and analysis. With features like bucket policies, lifecycle management, and cross-account access, S3 provides the storage foundation, while the actual querying is performed by tools like Athena.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not a log collection or analysis service. It performs automated security assessments against EC2 instances and container images, reporting findings such as CVE exposures and network reachability issues. Inspector does not ingest, store, or query central log streams, so it does not satisfy the requirement of centrally collecting and analyzing logs.
- ✗
AWS Shield
Why it's wrong here
AWS Shield is a managed DDoS protection service that safeguards applications running on AWS from distributed denial-of-service attacks. It provides always-on detection and automatic inline mitigation for network and transport layer attacks, with AWS Shield Advanced adding cost protection and attack diagnostics. Shield does not centrally aggregate or query logs from various accounts; it focuses solely on DDoS mitigation, making it irrelevant to the log collection and analysis use case in this question.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.