SCS-C02 Management and Security Governance Practice Question
Which TWO AWS services can be used to detect and alert on suspicious API activity in real-time? (Choose two.)
⚠ Common exam trap
SCS-C02 often tests the distinction between network-level monitoring (VPC Flow Logs) and API-level monitoring (CloudTrail/GuardDuty), causing candidates to select VPC Flow Logs for API activity detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail with CloudWatch Events
AWS CloudTrail with CloudWatch Events (A) is correct because CloudTrail records every API call as a management or data event, and CloudWatch Events (now EventBridge) can match those events in near real-time using rules and trigger alerts via SNS, Lambda, or other targets, enabling detection of suspicious API activity as it happens. Amazon GuardDuty (E) is correct because it continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs with threat intelligence and machine learning to detect anomalous or malicious API activity and generate findings in real time. VPC Flow Logs (B) only capture IP traffic metadata at the network interface level, not API-level activity, so they cannot directly detect suspicious API calls. Amazon S3 (C) is an object storage service and provides no native detection or alerting for API activity. AWS Config (D) evaluates resource configuration compliance and records configuration changes, but it is not designed for real-time detection and alerting on suspicious API behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail with CloudWatch Events
Why this is correct
AWS CloudTrail records all API activity across your account, including the identity making the call, source IP, timestamp, and the exact action performed. By creating a CloudWatch Events rule that filters for specific CloudTrail events—such as unauthorized PutBucketPolicy attempts, failed console logins, or IAM privilege escalation patterns—you can trigger near-real-time alerts through Amazon SNS, Lambda, or AWS Chatbot. This combination provides a native, low-latency pipeline to both detect and alert on suspicious management-plane activity.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic flowing to and from your virtual network interfaces, such as source/destination addresses, ports, protocol, and packet/byte counts. This telemetry is layer-3/4 network-level data and does not expose the content of API calls, nor does it correlate them with IAM identities. While VPC Flow Logs can reveal anomalies like a sudden spike to an unusual external IP, they cannot determine whether an AWS API request was malicious or unauthorized, so they are ineffective for alerting on suspicious API activity.
- ✗
Amazon S3
Why it's wrong here
Amazon S3 is a highly durable object storage service designed to store and retrieve data objects; it offers features like versioning, lifecycle policies, and server-side encryption. Although S3 can be configured to receive and store logs from other services, it does not itself analyze API activity or generate security alerts. It lacks the event-rule machinery and anomaly detection capabilities needed to continuously inspect AWS management-plane operations, so it is not a detection or alerting service.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration governance service that records resource configuration changes and evaluates them against custom or managed rules, such as requiring encrypted EBS volumes or denying public access to S3 buckets. Its scope is limited to the state and drift of resource configurations, not to the sequence or context of API calls. While AWS Config can trigger a reaction when a compliant configuration is changed, it does not detect suspicious identity behavior, credential misuse, or anomalous API patterns, so it does not satisfy the requirement.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty is a managed threat detection service that continuously consumes account telemetry, including AWS CloudTrail logs, VPC Flow Logs, and DNS query logs, and applies machine learning, anomaly detection, and threat intelligence. It can identify indicators like user credentials being used from an unusual geographic location, the execution of historical reconnaissance APIs, or the modification of GuardDuty itself—then generate findings. These findings can automatically trigger CloudWatch Events rules to send alerts, making GuardDuty one of the two services capable of detecting and alerting on suspicious API activity.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.