Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

Which TWO AWS services can be used to detect anomalous API calls in an AWS account?

⚠ Common exam trap

Many candidates confuse AWS Config's compliance evaluation (which checks resource configurations) with API call monitoring, leading them to select AWS Config instead of recognizing that only CloudTrail and GuardDuty (which uses CloudTrail logs and VPC Flow Logs for anomaly detection) can detect anomalous API calls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail with Amazon CloudWatch Logs metric filters.

AWS CloudTrail with Amazon CloudWatch Logs metric filters is correct because CloudTrail records all API calls, and you can create metric filters on CloudWatch Logs to match patterns indicative of anomalous activity (e.g., unauthorized API calls, root user activity). When the filter triggers a threshold, it can send an alarm via Amazon SNS, enabling detection of anomalous API calls in near real-time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail with Amazon CloudWatch Logs metric filters.

    Why this is correct

    CloudTrail records all AWS API activity, and when its logs are streamed to CloudWatch Logs, you can create metric filters that match patterns such as repeated AccessDenied errors or a high volume of failed AssumeRole calls. These metric filters feed CloudWatch alarms, enabling near-real-time detection of anomalous API call patterns without requiring external threat feeds or ML models.

  • ✗

    AWS Shield Advanced.

    Why it's wrong here

    AWS Shield Advanced is a managed DDoS protection service that mitigates volumetric and protocol attacks against your applications at the network and transport layers, with some layer 7 protection via integration with AWS WAF. It does not inspect the content of CloudTrail API events or use behavioral analysis to detect anomalous API activity; it only defends against resource exhaustion and availability threats, not against unusual control plane API call patterns.

  • ✓

    Amazon GuardDuty.

    Why this is correct

    Amazon GuardDuty continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS query logs using machine learning, anomaly detection, and threat intelligence to identify compromised credentials or unusual API activity. It can specifically flag API calls that deviate from established baselines, such as impossible-travel access, unusual geographic patterns, or the use of newly created keys, making it a native service that automatically detects anomalous API behavior without requiring you to define custom rules.

  • ✗

    AWS Config with managed rules.

    Why it's wrong here

    AWS Config records resource configuration changes and evaluates them against managed or custom rules to assess compliance, such as verifying that an S3 bucket is encrypted or that a security group does not allow unrestricted SSH access. Because it operates on the current state of resources rather than the continuous stream of API invocations, it cannot observe or flag anomalous API calls like multiple failed actions or unauthorized attempts.

  • ✗

    AWS WAF.

    Why it's wrong here

    AWS WAF filters and monitors HTTP(S) requests that are directed at your web application firewall, matching rules based on web request attributes such as IP addresses, headers, URI strings, or SQL injection signatures. It operates on the data plane for web traffic, not on the AWS control plane API logs, so it cannot identify anomalous API calls recorded by CloudTrail, which is why it is not a valid option for this scenario.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.