SCS-C02 Security Logging and Monitoring Practice Question
A company requires real-time analysis of AWS CloudTrail logs to detect unauthorized API calls. The logs are stored in Amazon S3. Which architecture minimizes latency and cost?
⚠ Common exam trap
Watch out — candidates often assume S3 event notifications (Option D) are the fastest path for real-time processing, but they overlook the inherent delivery delay of CloudTrail to S3 (up to 15 minutes) and the risk of Lambda concurrency limits causing dropped events under high log volume.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Send CloudTrail logs to Amazon CloudWatch Logs, then use a subscription filter to Amazon Kinesis Data Firehose delivering to Amazon OpenSearch Service
It provides the lowest-latency path for real-time analysis: CloudTrail logs are delivered to CloudWatch Logs in near real-time, and a subscription filter streams them to Kinesis Data Firehose, which buffers and delivers directly to Amazon OpenSearch Service for immediate indexing and search. This architecture avoids batch processing, minimizes data movement overhead, and uses managed services that scale automatically, keeping both latency and cost low.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Glue to crawl S3 and load into Amazon Redshift for analysis
Why it's wrong here
AWS Glue Crawlers discover schemas and AWS Glue ETL jobs process data in discrete, scheduled batches; they do not provide continuous event streaming. Loading into Amazon Redshift via COPY or Glue jobs likewise runs as a recurring batch load, adding latency that is incompatible with real-time analysis. This pipeline is appropriate for periodic data warehouse refreshes, not for a low-latency operational analytics feed.
- ✓
Send CloudTrail logs to Amazon CloudWatch Logs, then use a subscription filter to Amazon Kinesis Data Firehose delivering to Amazon OpenSearch Service
Why this is correct
CloudTrail can be configured to deliver events to Amazon CloudWatch Logs within minutes, and a subscription filter can immediately forward matching events to Amazon Kinesis Data Firehose. Firehose then buffers and delivers a continuous stream to Amazon OpenSearch Service, which indexes documents as they arrive for near-real-time search and visualization with OpenSearch Dashboards/Kibana. This managed pipeline gives the low-latency ingestion and querying the requirement asks for.
- ✗
Query CloudTrail logs directly using Amazon Athena
Why it's wrong here
Amazon Athena executes interactive SQL directly against files in Amazon S3, but each query starts cold over the objects already present and returns results after the scan completes. Athena has no push delivery, no automatic continuous query engine, and no built-in mechanism to re-run on new data without an external scheduler. Consequently it can provide fast ad-hoc analysis, but not the ongoing real-time stream analysis needed here.
- ✗
Configure S3 event notifications to invoke an AWS Lambda function that writes to Amazon OpenSearch Service
Why it's wrong here
Amazon S3 event notifications are asynchronous object-create events; CloudTrail log files are delivered to S3 in batched, aggregated files, so events arrive in chunks rather than as a real-time stream. Notifications can also be delayed or delivered at least once, and an invoker Lambda writing to Amazon OpenSearch Service may be throttled under high log volume. This design has no streaming semantics and cannot guarantee near-real-time visibility, unlike a CloudWatch Logs subscription feeding Firehose.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.