SCS-C02 Amazon GuardDuty Practice Question
Which TWO AWS services can be used to detect anomalous API activity in an AWS account? (Choose two.)
⚠ Common exam trap
The trap is that candidates may select VPC Flow Logs or AWS Config because they are associated with security monitoring, but they do not directly detect anomalous API activity. Additionally, some candidates might think only GuardDuty is a threat detection service and overlook that CloudTrail Insights also provides anomaly detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty (A) is correct because it is a managed threat-detection service that continuously analyzes CloudTrail management and data events, VPC Flow Logs, and DNS logs using machine learning and threat intelligence to identify anomalous or malicious API activity in the account. AWS CloudTrail (B) is correct because it records API calls as events and, through CloudTrail Insights, automatically detects unusual operational API activity such as spikes in write or error rates by baselining normal behavior. VPC Flow Logs (C) capture IP traffic metadata for network interfaces but do not analyze API calls, so they cannot detect anomalous API activity on their own. AWS Config (D) evaluates resource configuration compliance and changes, not API call behavior, so it is not a detection service for anomalous API activity. Amazon Inspector (E) scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure, not anomalous API usage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty continuously analyses CloudTrail management and data events, VPC Flow Logs and DNS logs using machine learning and threat intelligence to surface anomalous API activity. It satisfies the stem's detection requirement without agents or manual rule authoring, unlike CloudWatch alarms, which need explicit metric thresholds you define yourself.
- ✓
AWS CloudTrail
Why this is correct
CloudTrail records every API call as an event, providing the raw audit data that anomaly detection services analyse for unusual activity. Without this logging foundation, no behavioural baseline or deviation can be established, so it satisfies the detection requirement directly.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture IP-level metadata for traffic traversing elastic network interfaces, recording accepted and rejected connections rather than API calls; CloudTrail events never appear there. It is tempting because it supports network forensics and anomaly detection, and it would be correct for investigating unusual traffic flows to or from instances.
- ✗
AWS Config
Why it's wrong here
AWS Config continuously records resource configuration changes and evaluates them against rules; it tracks resource state, not the API call patterns that CloudTrail and GuardDuty analyse. It is tempting because it provides account-wide visibility, and it would be correct for detecting configuration drift or non-compliant resources.
- ✗
Amazon Inspector
Why it's wrong here
Inspector scans EC2 instances, container images and Lambda functions for software vulnerabilities and unintended network exposure; it does not analyse CloudTrail management events for anomalous API calls. It is tempting because it is a detection service, and it would be correct for identifying vulnerable workloads rather than suspicious API activity.
Visual reference
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.