Courseiva
Incident and Event Response →mediumMultiple Select

Alert on IAM Access Key Creation with CloudTrail and CloudWatch

A company uses AWS CloudTrail to log API activity. The security team wants to be alerted when an IAM user creates a new access key. Which TWO steps should be taken to accomplish this? (Choose TWO.)

⚠ Common exam trap

Watch out — candidates often confuse AWS Config rules (which check resource compliance) with CloudWatch Events (which react to API calls), leading them to choose Option D instead of the correct event-driven approach.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the CloudWatch Events rule to send a notification to an Amazon SNS topic.

Amazon CloudWatch Events (now Events) can be configured to match specific API calls logged by CloudTrail, such as CreateAccessKey. When the rule triggers, it can invoke an SNS topic to send an alert, enabling real-time notification. This approach directly monitors the API activity without additional overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable CloudTrail Insights to detect unusual activity in the account.

    Why it's wrong here

    CloudTrail Insights is designed to detect anomalous behavior by analyzing baseline patterns of write management events, not to match a specific, deterministic API call such as CreateAccessKey. It requires sufficient historical data to establish a baseline, and its output is an Insight event that indicates unusual activity, not a guaranteed notification for a fixed event type. Consequently, while Insights can alert broadly on abnormal access-key creation patterns, it cannot be configured to fire reliably on every CreateAccessKey call, making it inappropriate for this requirement.

  • ✓

    Configure the CloudWatch Events rule to send a notification to an Amazon SNS topic.

    Why this is correct

    Configuring a CloudWatch Events (now Amazon EventBridge) rule to send a notification to an Amazon SNS topic is a correct and recommended solution for this scenario. You define an event pattern that matches the CreateAccessKey event (source: iam.amazonaws.com, eventName: CreateAccessKey) and set the target to an SNS topic, which then delivers email, text, or other notifications to subscribers. This approach provides near-real-time, event-driven alerts directly from CloudTrail, with no dependence on polling or querying. It is the most direct way to satisfy the requirement of notifying the security team immediately when an access key is created.

  • ✓

    Create an Amazon CloudWatch Events rule that matches the CreateAccessKey API call via CloudTrail.

    Why this is correct

    Creating an Amazon CloudWatch Events rule that matches the CreateAccessKey API call via CloudTrail is a correct and essential first step in building an event-driven notification pipeline. The rule uses an event pattern to filter CloudTrail's management events, selecting only those with eventName equal to CreateAccessKey and source equal to iam.amazonaws.com. Once the rule matches the event, it can invoke a target such as an SNS topic, Lambda function, or other integration point. This approach leverages the real-time nature of CloudWatch Events and is the recommended pattern for triggering on specific AWS API activities, as opposed to log analysis or resource configuration evaluation.

  • ✗

    Create an AWS Config rule that checks for access key creation and sends an SNS notification.

    Why it's wrong here

    An AWS Config rule is intended to evaluate the configuration state of AWS resources and detect drift from desired settings; it does not monitor or react to API call events in real-time. For example, you could create a rule to check whether IAM users have access keys older than a defined max age, but that only reflects resource state at periodic evaluations or on configuration changes. When such a rule is non-compliant, it can send a notification via SNS, but this is not equivalent to detecting the moment CreateAccessKey is called. Therefore, using Config here would either miss immediate occurrences or introduce significant delay, and it does not align with the event-based alerting requirement.

  • ✗

    Use CloudWatch Logs Insights to run a query on the CloudTrail logs and set an alarm.

    Why it's wrong here

    CloudWatch Logs Insights is an interactive query engine for exploring and analyzing log data stored in CloudWatch Logs; it does not directly support setting alarms or sending real-time notifications. To alert on a specific event using logs, you would first need to create a CloudWatch Logs metric filter, such as filtering CloudTrail log events for CreateAccessKey, and then define a CloudWatch alarm based on that metric. The alarm, not Logs Insights, would ultimately trigger an SNS notification, and even this approach has higher latency and complexity compared to an EventBridge rule. The option as stated is incorrect because it relies on Logs Insights alone, which lacks both real-time monitoring and alarm capabilities.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.