Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company needs to be alerted when root account credentials are used in their AWS account. Which service should be used to create a metric filter and alarm for this event?

⚠ Common exam trap

Test-takers frequently confuse CloudTrail (the log source) with CloudWatch Logs (the service that processes and alerts on logs), assuming CloudTrail itself can create alarms when it only delivers logs to S3 or CloudWatch Logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Logs

Amazon CloudWatch Logs can monitor CloudTrail log events for root account usage by creating a metric filter that matches the `userIdentity.type` field with a value of `Root`. When the filter detects a match, it triggers a CloudWatch alarm to notify the operations team. This is the standard AWS-recommended approach for alerting on root activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty provides intelligent threat detection using machine learning and continuously analyzes CloudTrail management events, VPC flow logs, and DNS logs. It can generate managed findings such as 'RootCredentialUsage' to signal suspicious root activity, but it relies on predefined detectors and does not expose raw CloudTrail log content as custom metric filters. For a custom, rule-based alert on exact root login patterns, you need CloudWatch Logs metric filters and alarms instead.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config evaluates the recorded configuration state of AWS resources, such as whether an IAM user has an access key or MFA, against managed or custom rules. It can detect when the root user has long-term credentials and enforce compliance policies, but it does not inspect real-time API call events or sign-in sessions from CloudTrail logs. The scenario demands an event-driven alert on credential usage, which is outside Config's configuration-change monitoring model.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail continuously records API activity and user sign-in events to a log file or CloudWatch Logs log group, including console logins by the root account as events with userIdentity.type set to 'Root'. However, CloudTrail is only a logging service; it has no native mechanism to evaluate log content, compare thresholds, or trigger an alert. To alert on root credential usage, you must configure a CloudWatch Logs metric filter and alarm that processes the CloudTrail events after they have been delivered.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    Amazon CloudWatch Logs can receive CloudTrail events and apply a metric filter, for example matching $.userIdentity.type = 'Root' and $.eventName = 'ConsoleLogin', to count root credential activity. A CloudWatch alarm on that metric threshold can then trigger an SNS notification to alert the company in near real time. This is the correct service because it directly enables custom, log-driven alerting on the root account usage pattern.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.