Courseiva
Monitoring and Logging →mediumMultiple Choice

DOP-C02 Monitoring and Logging Practice Question

A company uses AWS CloudTrail to log all API calls in their AWS account. They need to ensure that any changes to CloudTrail configuration (such as disabling the trail or modifying the log file validation) are immediately detected and trigger an automated response. Which solution should the DevOps engineer implement?

⚠ Common exam trap

The trap is confusing monitoring services like GuardDuty or Config with real-time event-driven detection; candidates may pick Config because it can detect changes, but it lacks the immediate EventBridge-based response required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Amazon EventBridge rule that matches CloudTrail API calls like StopLogging or UpdateTrail and triggers an SNS topic.

Amazon EventBridge can match AWS CloudTrail API calls such as StopLogging or UpdateTrail and trigger an SNS topic for immediate notification and automated response. This provides real-time detection of changes to CloudTrail configuration, satisfying the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Amazon GuardDuty and configure it to monitor CloudTrail logs for suspicious activity.

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that consumes CloudTrail management events, VPC Flow Logs, and DNS logs to identify suspicious behavior such as compromised credentials or crypto-mining activity. It does not have built-in checks for configuration drift or trail health, and it cannot generate a targeted alert when a trail is stopped or updated. GuardDuty may eventually flag anomalous API patterns, but its focus is on malicious activity, not on maintaining the integrity of the CloudTrail configuration itself, so it would not satisfy the real-time notification requirement.

  • ✓

    Create an Amazon EventBridge rule that matches CloudTrail API calls like StopLogging or UpdateTrail and triggers an SNS topic.

    Why this is correct

    Amazon EventBridge can natively consume CloudTrail management events and evaluate them against a rule with an event pattern that matches specific API calls such as StopLogging or UpdateTrail. Because the rule is event-driven, it triggers an SNS topic within seconds of the incident, enabling immediate notification to security operations. This approach requires no polling or configuration state evaluation, making it the most direct real-time mechanism for responding to changes to CloudTrail itself.

  • ✗

    Use AWS Config rules with remediation actions to detect and revert changes to CloudTrail.

    Why it's wrong here

    AWS Config rules are resource-based and assess the configuration state of resources against desired policies, checking a trail for loggingEnabled or some other compliance field. They are evaluated on a periodic schedule (for example, every hour) or when a configuration change is detected, but never as a direct reaction to an API call event. A remediation action would only run after the rule has identified the trail as non-compliant, introducing an unavoidable delay that prevents the kind of immediate alerting offered by EventBridge. Additionally, you would need to author a custom rule to detect the specific configuration, whereas EventBridge already sees the raw API event.

  • ✗

    Use AWS Trusted Advisor to check CloudTrail configuration and send alerts via email.

    Why it's wrong here

    AWS Trusted Advisor runs a set of best-practice checks on a periodic basis and covers categories like cost optimization, security, and fault tolerance, but it does not include a check for CloudTrail trail health or API-call-level activity. Any alerts Trusted Advisor sends via email or weekly digest are based on those infrequent checks, not on real-time events, and it cannot be configured to react to a specific StopLogging call. Therefore, Trusted Advisor cannot provide the instantaneous notification required by the use case.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.