SCS-C02 Security Logging and Monitoring Practice Question
A company is using AWS CloudTrail to monitor API activity. The security team wants to be alerted when an IAM user creates a new access key. Which CloudTrail event should be used to create a CloudWatch Events rule?
⚠ Common exam trap
Many exam-takers confuse UpdateAccessKey with CreateAccessKey, thinking that updating a key includes creation, but UpdateAccessKey only modifies the key's status (e.g., Active/Inactive) and does not generate a new key pair.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CreateAccessKey
The correct event is CreateAccessKey because this is the specific CloudTrail event that is logged when an IAM user creates a new access key. CloudTrail captures this API call as a management event, and a CloudWatch Events rule can be configured to match this event name to trigger an alert. The security team's requirement is to detect the creation of access keys, which is directly represented by the CreateAccessKey event.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EnableMFADevice
Why it's wrong here
The EnableMFADevice event is logged when an IAM user calls the EnableMFADevice API to activate an MFA device, such as a virtual or hardware token. It does not create or rotate any access key; instead, it associates a multi-factor authentication device with a user. Because the question asks specifically about access key creation, this event name is inconsistent with the required API action. Therefore, it is incorrect.
- ✗
UpdateAccessKey
Why it's wrong here
The UpdateAccessKey event corresponds to the IAM UpdateAccessKey API, which only changes the status of an existing access key between Active and Inactive. No new secret access key is generated, and the key material remains unchanged. CloudTrail records this as a separate event type from creation, so it cannot be the event that indicates a new access key was created. Hence, this option is wrong.
- ✗
UploadSigningCertificate
Why it's wrong here
The UploadSigningCertificate event is generated when an IAM user uploads an X.509 certificate to use for AWS API requests, not when an access key is created. Signing certificates are a distinct authentication credential from access keys, which consist of an access key ID and a secret access key. The CloudTrail event name exactly matches the UploadSigningCertificate API call, so it would not be logged for a create-access-key operation. This option is therefore incorrect.
- ✓
CreateAccessKey
Why this is correct
The CreateAccessKey event is logged by CloudTrail when an IAM user or role calls the CreateAccessKey API to generate a new access key pair. This is precisely the event that indicates creation of a new access key, making it the correct answer. Note that while CloudTrail records the access key ID in the event, the secret access key is not logged; it is displayed only once at creation time. This event is also useful for detecting unauthorized credential creation.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.