Courseiva
Security Logging and MonitoringhardMultiple ChoiceObjective-mapped

Real-Time Alerting for Security Group Modifications with EventBridge

A company runs a critical application on Amazon EC2 instances in an Auto Scaling group. The security team needs to monitor for unauthorized changes to security groups. They have enabled AWS Config with the security-group-change detection rule. However, they notice that changes are being detected but not all changes trigger a notification. The team wants to ensure that every security group modification (create, delete, or rule change) sends an alert to the security operations center via Amazon SNS. The current setup: AWS Config rules evaluate resources periodically, and SNS notifications are sent only when the rule compliance status changes. What should the team do to achieve real-time alerts for all security group changes?

Quick Answer

The gap in the existing setup is that AWS Config rules, even ones built to detect security group changes, are evaluated periodically and only send a notification when a resource's overall compliance status changes, so rapid or repeated modifications to the same resource can slip through without a fresh alert each time. Amazon EventBridge solves this because it doesn't wait for a periodic evaluation cycle; it reacts directly to the CloudTrail record of the API call, so a rule matching security-group-modification events, whether a create, delete, or rule change, fires immediately when the call happens and can push a notification to SNS in near real time. This is the core distinction between compliance monitoring and event-driven monitoring: Config tells you the current state of a resource and flags when that state becomes non-compliant, while CloudTrail-plus-EventBridge tells you the instant a specific action occurs, regardless of whether it changes an overall compliance verdict. The other options don't close this gap: GuardDuty detects threats rather than serving as a general change-monitoring tool, and VPC Flow Logs record network traffic, not the API calls that modify security group rules. Whenever a periodic tool misses changes and the requirement is alerts on every occurrence in real time, look for a solution matching the relevant API call as it happens, which is what an EventBridge rule sourced from CloudTrail does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure an Amazon EventBridge rule that matches API calls via CloudTrail for security group modifications and sends notifications to an SNS topic.

CloudTrail logs all API calls, including security group modifications, in real time. By creating an Amazon EventBridge rule that matches SecurityGroup events and targets an SNS topic, the team can receive immediate notifications. Option A is incorrect because GuardDuty focuses on threat detection (e.g., suspicious API activity), not on monitoring all security group configuration changes. Option C is incorrect because even with frequent evaluations, AWS Config rules evaluate configuration snapshots periodically and do not provide real-time alerting for each change. Option D is incorrect because VPC Flow Logs monitor network traffic, not security group modifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploy Amazon GuardDuty and enable the Security Group Monitoring feature.

    Why it's wrong here

    GuardDuty focuses on threat detection (e.g., suspicious API activity), not on monitoring all security group configuration changes. It does not have a 'Security Group Monitoring feature' and does not provide real-time alerts for every security group modification.

  • Configure an Amazon EventBridge rule that matches API calls via CloudTrail for security group modifications and sends notifications to an SNS topic.

    Why this is correct

    CloudTrail logs all API calls, including security group modifications, in real time. An EventBridge rule can match these events and trigger an SNS notification, ensuring immediate alerts for every change.

  • Increase the frequency of AWS Config rule evaluations to every minute to reduce detection latency.

    Why it's wrong here

    Even with increased evaluation frequency, AWS Config rules evaluate configuration snapshots periodically and do not provide real-time alerting for each individual change. They are designed for compliance assessment, not real-time monitoring.

  • Enable VPC Flow Logs and set up a metric filter for security group-related traffic anomalies.

    Why it's wrong here

    VPC Flow Logs monitor network traffic (IP traffic) and are not capable of detecting changes to security group configurations. They do not provide alerts for security group modifications.

About these practice questions

One of 376 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security engineer needs to be alerted when an IAM user attempts to modify an S3 bucket policy. Which method is the MOST efficient?

easy
  • A.Enable VPC Flow Logs and analyze for S3 API traffic
  • B.Configure an AWS Config rule to detect changes and invoke a Lambda function
  • C.Create an Amazon CloudWatch Events rule that matches the PutBucketPolicy API call and triggers an SNS notification
  • D.Enable S3 server access logs and parse them for PutBucketPolicy entries

Why C: Amazon CloudWatch Events (now Amazon EventBridge) can directly capture the PutBucketPolicy API call as a real-time event and trigger an SNS notification without any additional compute or polling. This is the most efficient method as it requires no log parsing, no custom code, and no additional infrastructure, providing immediate alerting with minimal overhead.

Variation 2. A company uses AWS CloudTrail to log all API calls. The security team needs to be alerted when an IAM user creates a new access key. Which approach is most efficient?

medium
  • A.Enable AWS Config managed rule to detect access key creation and trigger an SNS notification.
  • B.Create a CloudWatch Events rule that matches the CreateAccessKey event and targets an SNS topic.
  • C.Use CloudWatch Logs Insights to run a query every minute on CloudTrail logs and send results to SNS.
  • D.Configure CloudTrail to send logs to an S3 bucket and enable S3 event notifications to an SNS topic.

Why B: CloudWatch Events (now part of Amazon EventBridge) can directly match the CreateAccessKey API call from AWS CloudTrail in real time and trigger an SNS notification. This approach is the most efficient as it requires no polling, no additional infrastructure, and provides immediate alerting with minimal latency.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.