Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A SysOps administrator is investigating a security incident where an EC2 instance was used to launch an attack. The administrator needs to determine the source IP addresses that were used to access the instance prior to the attack. Which AWS service and feature should be used to capture this information?

⚠ Common exam trap

A common mix-up: candidates confuse AWS CloudTrail (which logs API calls) with network traffic logging, mistakenly thinking CloudTrail captures IP-level traffic data, when in fact only VPC Flow Logs record the actual source IP addresses of network connections to an EC2 instance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Flow Logs

VPC Flow Logs capture metadata about IP traffic flowing to and from network interfaces in a VPC, including the source IP address, destination IP address, port, protocol, and timestamps. This allows the administrator to identify the source IP addresses that accessed the EC2 instance prior to the attack, as the logs record all accepted and rejected traffic at the network interface level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that uses machine learning and anomaly detection to generate findings from data sources like VPC Flow Logs, CloudTrail, and DNS logs. It provides alerts about potential threats, but it does not store or expose the raw flow log data itself for detailed analysis. You would still need to enable VPC Flow Logs separately to obtain the underlying network metadata required for a thorough forensic investigation.

  • ✗

    AWS CloudTrail with data events enabled for EC2

    Why it's wrong here

    AWS CloudTrail does not support data events for EC2 instances in the way it does for S3 object-level or Lambda invocations; even with data events enabled, CloudTrail records API operations such as RunInstances or TerminateInstances, not the actual network traffic. This means it captures who performed management actions and when, but it cannot reveal source IPs, ports, or protocols involved in a security incident. Therefore, CloudTrail is not the correct tool for analyzing traffic flow.

  • ✓

    VPC Flow Logs

    Why this is correct

    VPC Flow Logs capture metadata about IP traffic flowing to and from network interfaces in a VPC, including source and destination IP addresses, ports, protocol, and whether the traffic was accepted or rejected. These logs can be published to Amazon CloudWatch Logs or Amazon S3, and they are the standard AWS service for retracing actual network activity during a security investigation. Unlike API logs or configuration records, VPC Flow Logs directly answer the need to identify which source IPs communicated with your resources.

  • ✗

    AWS Config with recording of security groups

    Why it's wrong here

    AWS Config records configuration changes for AWS resources, including security group rules, but it does not record network traffic or packet-level data. While you could use Config to determine what security group rules were in effect at a given time, it cannot tell you which connections were actually attempted, accepted, or denied. Config is a compliance and configuration tracking service, not a network traffic logging service, so it is unsuitable for investigating the specifics of a security incident.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.