Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company's security team is investigating a potential security incident. They have enabled CloudTrail and CloudWatch Logs. They want to receive real-time alerts when an IAM user creates a new access key. Which combination of services should be used to achieve this?

⚠ Common exam trap

Test-takers frequently confuse AWS Config (which monitors configuration changes) with CloudTrail (which records API calls), or assume GuardDuty covers all security events, but GuardDuty does not provide granular, custom alerts on specific IAM actions like access key creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudTrail with CloudWatch Logs, metric filter, alarm, and SNS topic

CloudTrail logs API calls like CreateAccessKey to CloudWatch Logs. A metric filter on the event name 'CreateAccessKey' triggers a CloudWatch alarm that publishes to an SNS topic, enabling real-time notifications. This is the standard AWS architecture for real-time alerting on specific IAM actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config rules with an SNS topic

    Why it's wrong here

    AWS Config rules operate by evaluating the configuration state of AWS resources against managed or custom rules, such as checking whether an S3 bucket is publicly accessible or an IAM role is overly permissive. They do not capture or analyze the API call stream itself, so they cannot directly detect a specific action like 'DeleteBucket' or 'PutBucketPolicy' unless a custom rule is configured to query CloudTrail logs. Merely subscribing an SNS topic to AWS Config notifications provides compliance status changes, not real-time alerts about a particular API call.

  • ✗

    Amazon GuardDuty with an SNS topic

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that ingests and analyzes CloudTrail management events, VPC flow logs, and DNS logs to identify suspicious behavior such as unusual geolocations, cryptomining activity, or compromised credentials. It can publish findings to an SNS topic, but its detections are based on machine learning and threat intelligence rather than exact API names or deterministic event matching. Therefore, it cannot be configured to alert when a specific API call is made by a specific IAM user or at a precise frequency; it is designed for broader anomaly detection, not precise API-level alerting.

  • ✓

    CloudTrail with CloudWatch Logs, metric filter, alarm, and SNS topic

    Why this is correct

    This is the correct end-to-end solution: AWS CloudTrail records every management API call and delivers those logs to a CloudWatch Logs log group. A CloudWatch Logs metric filter is then created with a pattern that matches the specific event, for example the eventName or a user identity, and the filter publishes a metric value each time a matching event occurs. A CloudWatch alarm can then monitor that metric with a defined threshold, and when triggered, it sends a notification to an SNS topic, enabling real-time alerting for the exact API call of interest.

  • ✗

    CloudTrail with Lambda function invocation

    Why it's wrong here

    CloudTrail cannot directly invoke a Lambda function when an API call is made; the CloudTrail event stream is not a native event source for Lambda. To trigger a Lambda on a CloudTrail event, you must relay the logs through CloudWatch Logs and use a subscription filter, or use an Amazon EventBridge rule that matches the API call and targets the Lambda function. The proposed option, without such a middleware layer, is incomplete and will not function, whereas the correct design uses CloudWatch Logs as the delivery and filtering engine.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.