Courseiva

SCS-C02 Management and Security Governance Practice Question

Which TWO AWS services can be used to detect and alert on suspicious API activity in real-time? (Choose two.)

⚠ Common exam trap

SCS-C02 often tests the distinction between network-level monitoring (VPC Flow Logs) and API-level monitoring (CloudTrail/GuardDuty), causing candidates to select VPC Flow Logs for API activity detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail with CloudWatch Events

AWS CloudTrail with CloudWatch Events (A) is correct because CloudTrail records every API call as a management or data event, and CloudWatch Events (now EventBridge) can match those events in near real-time using rules and trigger alerts via SNS, Lambda, or other targets, enabling detection of suspicious API activity as it happens. Amazon GuardDuty (E) is correct because it continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs with threat intelligence and machine learning to detect anomalous or malicious API activity and generate findings in real time. VPC Flow Logs (B) only capture IP traffic metadata at the network interface level, not API-level activity, so they cannot directly detect suspicious API calls. Amazon S3 (C) is an object storage service and provides no native detection or alerting for API activity. AWS Config (D) evaluates resource configuration compliance and records configuration changes, but it is not designed for real-time detection and alerting on suspicious API behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail with CloudWatch Events

    Why this is correct

    AWS CloudTrail records all API activity across your account, including the identity making the call, source IP, timestamp, and the exact action performed. By creating a CloudWatch Events rule that filters for specific CloudTrail events—such as unauthorized PutBucketPolicy attempts, failed console logins, or IAM privilege escalation patterns—you can trigger near-real-time alerts through Amazon SNS, Lambda, or AWS Chatbot. This combination provides a native, low-latency pipeline to both detect and alert on suspicious management-plane activity.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic flowing to and from your virtual network interfaces, such as source/destination addresses, ports, protocol, and packet/byte counts. This telemetry is layer-3/4 network-level data and does not expose the content of API calls, nor does it correlate them with IAM identities. While VPC Flow Logs can reveal anomalies like a sudden spike to an unusual external IP, they cannot determine whether an AWS API request was malicious or unauthorized, so they are ineffective for alerting on suspicious API activity.

  • ✗

    Amazon S3

    Why it's wrong here

    Amazon S3 is a highly durable object storage service designed to store and retrieve data objects; it offers features like versioning, lifecycle policies, and server-side encryption. Although S3 can be configured to receive and store logs from other services, it does not itself analyze API activity or generate security alerts. It lacks the event-rule machinery and anomaly detection capabilities needed to continuously inspect AWS management-plane operations, so it is not a detection or alerting service.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a configuration governance service that records resource configuration changes and evaluates them against custom or managed rules, such as requiring encrypted EBS volumes or denying public access to S3 buckets. Its scope is limited to the state and drift of resource configurations, not to the sequence or context of API calls. While AWS Config can trigger a reaction when a compliant configuration is changed, it does not detect suspicious identity behavior, credential misuse, or anomalous API patterns, so it does not satisfy the requirement.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is a managed threat detection service that continuously consumes account telemetry, including AWS CloudTrail logs, VPC Flow Logs, and DNS query logs, and applies machine learning, anomaly detection, and threat intelligence. It can identify indicators like user credentials being used from an unusual geographic location, the execution of historical reconnaissance APIs, or the modification of GuardDuty itself—then generate findings. These findings can automatically trigger CloudWatch Events rules to send alerts, making GuardDuty one of the two services capable of detecting and alerting on suspicious API activity.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.