DVA-C02 Security Practice Question
A company uses AWS CloudTrail to log all API calls. The security team wants to be notified immediately when an IAM user creates a new access key. Which solution is most efficient?
⚠ Common exam trap
Candidates often default to CloudWatch Logs metric filters (Option A) because they are familiar, but fail to recognize that EventBridge rules provide a simpler, lower-latency, and more cost-effective solution for real-time API call monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudWatch Events rule that matches the CreateAccessKey API call and triggers a Lambda function to send an SNS notification.
CloudWatch Events (now Amazon EventBridge) can directly match the CreateAccessKey API call from CloudTrail and trigger a Lambda function to send an SNS notification in near real-time. This is the most efficient solution as it avoids the overhead of log ingestion, metric filters, or periodic queries, providing immediate notification with minimal latency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure CloudTrail to send logs to CloudWatch Logs and create a metric filter with an alarm.
Why it's wrong here
While CloudTrail can forward logs to CloudWatch Logs, and a metric filter can indeed trigger an alarm based on specific log patterns like CreateAccessKey, this approach introduces a slight processing delay. CloudWatch Logs needs to ingest, index, and then apply the metric filter to the log events, making it less immediate than a direct event-driven solution for real-time security alerts. This latency can be critical for sensitive API calls.
- ✓
Create a CloudWatch Events rule that matches the CreateAccessKey API call and triggers a Lambda function to send an SNS notification.
Why this is correct
This is the most effective solution for real-time security notifications. CloudWatch Events (now Amazon EventBridge) can directly consume CloudTrail management events as they occur, allowing for immediate pattern matching on specific API calls like CreateAccessKey. Upon a match, it can instantly invoke a Lambda function, which then sends an SNS notification, ensuring near-instantaneous alerting for critical security events.
- ✗
Enable CloudTrail log file validation and periodically check the logs.
Why it's wrong here
Enabling CloudTrail log file validation ensures the integrity of the log files, confirming they haven't been tampered with after delivery to S3. However, this feature does not provide real-time alerting; it's a post-event verification mechanism. Periodically checking logs, whether manually or via a scheduled script, inherently introduces significant delays, making it unsuitable for immediate security incident response.
- ✗
Use Amazon Athena to query CloudTrail logs daily.
Why it's wrong here
Amazon Athena is an interactive query service that makes it easy to analyze data directly in Amazon S3 using standard SQL. While excellent for ad-hoc analysis, auditing, or forensic investigations of historical CloudTrail logs, querying them daily is a batch process. This approach introduces a delay of up to 24 hours between the API call and its detection, which is unacceptable for real-time security monitoring and immediate incident response.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.