Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company is using Amazon Macie to discover sensitive data in S3. The security team wants to be notified when Macie finds a high-severity alert. Which integration should be used?

⚠ Common exam trap

Candidates often assume Macie findings must go through Security Hub or CloudWatch first, but EventBridge is the native event bus for all AWS services including Macie, and it directly supports SNS as a target without custom actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Amazon EventBridge rule that matches Macie findings and targets an SNS topic.

Amazon EventBridge can directly capture Macie findings (which are emitted as events) and route them to an SNS topic for notification. This is the native, event-driven integration that requires no intermediate storage or custom actions, making it the simplest and most reliable approach for real-time alerting on high-severity findings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Macie to store findings in an S3 bucket and enable S3 event notifications.

    Why it's wrong here

    Macie does not have a native setting to write findings to an S3 bucket; findings are stored in the Macie service and retrievable via the console and API. S3 event notifications fire on object-level operations such as PUT or DELETE, not on Macie finding generation. To land findings in S3 you would need an intermediate step, such as an EventBridge rule invoking a Lambda function to copy the finding payload into a bucket.

  • ✗

    Integrate Macie with AWS Security Hub and create a custom action to send to SNS.

    Why it's wrong here

    This path is indirect and unnecessary: Macie natively publishes findings to EventBridge, and Security Hub simply consumes those findings from EventBridge after ingestion. Security Hub custom actions only re-emit Security Hub findings as events for downstream automation, which adds latency and requires Security Hub to be enabled and finding ingestion to complete. For real-time Macie-to-SNS alerting, an EventBridge rule directly targeting SNS is simpler and avoids the extra aggregation hop.

  • ✓

    Create an Amazon EventBridge rule that matches Macie findings and targets an SNS topic.

    Why this is correct

    Macie automatically publishes every finding to Amazon EventBridge as a 'Macie Finding' event on the default event bus. An EventBridge rule with an event pattern matching source 'aws.macie' and detail-type 'Macie Finding' can route to an SNS topic in near real time. This is the native integration path, requiring no additional services, custom code, or intermediate storage.

  • ✗

    Configure Macie to send findings to CloudWatch Logs and create a metric filter.

    Why it's wrong here

    Macie has no native CloudWatch Logs destination; findings are published exclusively to EventBridge. While you could theoretically create an EventBridge rule that targets CloudWatch Logs and then apply a metric filter, that is an artificial pipeline Macie cannot configure directly. CloudWatch metric filters operate on ingested log text, but Macie never writes its finding JSON to a log group natively, so the premise is invalid.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.