Courseiva
Monitoring and Logging →mediumMultiple Choice

DOP-C02 Monitoring and Logging Practice Question

A company uses AWS CloudTrail to log API activity. The security team needs to be alerted when an IAM user creates a new access key. How can this be achieved with minimal overhead?

⚠ Common exam trap

Watch out — candidates often confuse AWS Config (which evaluates resource state) with EventBridge (which evaluates API events), leading them to choose Option B, but Config cannot react to API calls in real-time and is not designed for event-driven alerting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Amazon EventBridge rule that matches the 'CreateAccessKey' event and targets an SNS topic.

D is correct because Amazon EventBridge can capture real-time CloudTrail API events, such as 'CreateAccessKey', and route them directly to an SNS topic for immediate notification. This approach requires no polling, no custom code, and minimal overhead, as EventBridge handles event matching and delivery natively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use CloudWatch Logs Insights to run a query every hour and send results via email.

    Why it's wrong here

    Running a CloudWatch Logs Insights query on an hourly schedule is asynchronous and not near-real-time; between the API call and the next query invocation, a malicious access key could be used for up to an hour. Additionally, this approach requires a custom scheduler (e.g., EventBridge scheduler) to invoke the query and send email, and CloudWatch Logs Insights is designed for ad-hoc log analysis rather than event-driven security alerting.

  • ✗

    Set up an AWS Config rule to detect when an access key is created.

    Why it's wrong here

    AWS Config rules evaluate the compliance of AWS resource configuration state, not transient API events, so they cannot directly detect the moment a CreateAccessKey call occurs. While Config can record changes to IAM access keys as configuration items, it operates on a periodic or configuration-change basis, which is not suitable for immediate, event-driven alerting and would require a custom conformance pack plus Lambda remediation to approximate a notification.

  • ✗

    Configure S3 event notifications on the CloudTrail bucket to trigger a Lambda function.

    Why it's wrong here

    S3 event notifications trigger on object lifecycle events such as s3:ObjectCreated:* in the CloudTrail logging bucket, not on individual AWS API calls like CreateAccessKey. CloudTrail writes log files in batches every few minutes, so the Lambda would only fire after the log file is delivered and then would need to parse the entire file to find the event, introducing latency and processing cost. This design is inherently indirect and misses the security-relevant near-real-time requirement.

  • ✓

    Create an Amazon EventBridge rule that matches the 'CreateAccessKey' event and targets an SNS topic.

    Why this is correct

    An EventBridge rule with an event pattern that matches the AWS API-call event for 'CreateAccessKey' (specifically detail.eventSource for iam.amazonaws.com and detail.eventName) synchronously triggers an SNS topic, delivering email or other notifications in near-real-time. This is the natively supported pattern for reacting to CloudTrail API activity, as CloudTrail forwards events to EventBridge, and it is fully serverless with no polling or log-parsing required.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.