Courseiva
Question 1,667 of 1,621
Network Security, Compliance and GovernancemediumMultiple ChoiceObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A company wants to audit all changes to security groups in their AWS account. They need to be notified whenever a security group rule is added, modified, or removed. They also want to see who made the change. Which solution should they implement?

⚠ Common exam trap

Watch out — candidates often confuse AWS Config's configuration tracking (which detects drift but not per-event user identity) with CloudTrail's API-level audit trail, or they mistakenly think VPC Flow Logs can capture security group changes when they only capture traffic metadata.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable AWS CloudTrail and create a CloudWatch Events rule that triggers on EC2 SecurityGroup events, sending notifications via SNS.

AWS CloudTrail captures all API calls, including EC2 SecurityGroup-related actions (AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress, etc.), recording the identity of the caller. A CloudWatch Events rule can filter for these specific events and trigger an SNS notification, providing both the change details and the IAM user or role that made the change. This meets the audit and notification requirements precisely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use AWS Trusted Advisor to check for security group changes and send email alerts.

    Why it's wrong here

    Trusted Advisor does not monitor real-time changes; it provides periodic checks.

  • Use AWS Config to monitor security group changes and trigger a Lambda function to send notifications.

    Why it's wrong here

    AWS Config can detect changes but is not real-time and does not directly provide who made the change; it shows configuration changes but not the principal.

  • Enable AWS CloudTrail and create a CloudWatch Events rule that triggers on EC2 SecurityGroup events, sending notifications via SNS.

    Why this is correct

    CloudTrail logs API calls to create, modify, and delete security group rules. CloudWatch Events can filter on these events and send to SNS for notification.

  • Enable VPC Flow Logs and analyze logs for changes to security group rules.

    Why it's wrong here

    Flow Logs capture network traffic, not security group rule changes.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 24, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.