SCS-C03 Detection Practice Question
Exhibit
2023-10-27T10:00:00Z | User: Admin | Action: DeleteTable | Resource: DynamoDB | Status: Denied
Refer to the exhibit. The log entry shows a denied 'DeleteTable' attempt. Which service, if configured, would have automatically triggered an alert based on this specific log entry?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Metric Filters and Alarms.
This log entry represents an unauthorized attempt to modify critical infrastructure. To alert on this, one must integrate CloudTrail with Amazon CloudWatch Logs and establish a Metric Filter that matches the 'Denied' status and the 'DeleteTable' action. This pattern is essential for incident response, as it allows security teams to distinguish between accidental user error and potential malicious reconnaissance or destructive intent by an insider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty.
Why it's wrong here
GuardDuty is optimized for identifying anomalous patterns like unusual API calls or credential theft, but it does not allow users to define custom metric filters for specific log patterns. It would not specifically alert on a single 'Denied' event unless that event is part of a larger, suspicious behavioral pattern.
- ✓
Amazon CloudWatch Metric Filters and Alarms.
Why this is correct
CloudWatch Metric Filters allow users to search CloudTrail logs for specific patterns, such as denied API calls. Once a pattern is matched, a metric can be incremented and an alarm can be configured to notify security personnel, providing an automated way to detect high-risk denied actions.
- ✗
AWS Security Hub.
Why it's wrong here
While Security Hub aggregates findings, it does not act as the primary engine for creating custom alerts based on raw log patterns. To get an alert into Security Hub, the log must first be processed by another service, such as CloudWatch or Lambda, to generate a formal finding.
- ✗
AWS Trusted Advisor.
Why it's wrong here
Trusted Advisor checks for resource optimization and security best practices, but it does not monitor real-time API logs or provide alerting capabilities for specific denied events within an account. It is not designed to function as an incident detection tool for API authorization failures.
About these practice questions
This SCS-C03 question is part of Courseiva's 99-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.