Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses AWS CloudTrail to log all API activity. The security team wants to be alerted when an IAM user creates a new access key. They have created a CloudWatch metric filter on the CloudTrail log group for the event name 'CreateAccessKey' and set up a CloudWatch alarm that sends an email via Amazon SNS. However, the alarm is not triggering even though the team knows that access keys have been created. The metric filter has been tested and shows data points in CloudWatch. What should the security team check next?

⚠ Common exam trap

A common mix-up: candidates assume the issue must be with log delivery or event type, but the metric filter already shows data points, so the problem lies in the alarm's evaluation configuration—specifically the period and threshold settings that control when the alarm triggers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the CloudWatch alarm configuration, including the period and threshold.

The metric filter is producing data points, which means logs are being ingested and the filter is matching events. The most likely issue is that the CloudWatch alarm's period or threshold is misconfigured—for example, the evaluation period might be too long or the threshold too high, causing the alarm to not transition to ALARM state despite the metric having values. The security team should verify the alarm's settings, such as the period (e.g., 5 minutes) and the threshold (e.g., >= 1), to ensure they align with the expected frequency of access key creation events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensure that the CloudTrail trail is delivering logs to the correct CloudWatch Logs log group.

    Why it's wrong here

    The CloudTrail trail delivering logs to the correct CloudWatch Logs log group is a prerequisite for the metric filter to see events, but the existing evidence indicates the metric filter is already showing data. If the log group were wrong or delivery were broken, the metric would have no values at all; an alarm that fails to trigger while metrics exist points away from the delivery path. Changing delivery or log group would not affect the alarm if the metric is present, so this fix does not address the reported symptom.

  • ✗

    Verify that the CloudTrail trail is logging data events.

    Why it's wrong here

    CloudTrail classifies CreateAccessKey as a management event, not a data event, and management events are recorded by default whenever a trail is active. Data event logging is an optional setting for S3 object-level operations, Lambda invocations, or DynamoDB item-level access, and it has no bearing on an IAM console or SDK call like CreateAccessKey. Verifying data events would not help because the metric filter is targeting a management event that is already captured under default settings.

  • ✓

    Review the CloudWatch alarm configuration, including the period and threshold.

    Why this is correct

    Once the metric filter confirms that the CreateAccessKey events are being published to CloudWatch, the alarm logic itself is the next layer to inspect. A period that is too long, a threshold set above the number of events in the window, or an inappropriate statistic (such as Average instead of Sum) can keep the alarm in OK even though events are occurring. Also, the alarm must be configured with a ComparisonOperator and EvaluationPeriods that reflect the expected bursty nature of access-key creation; one event in a five-minute period will never breach a threshold of 1 if the metric is evaluated every minute.

  • ✗

    Check that the IAM user has permissions to create access keys.

    Why it's wrong here

    Whether the IAM user is allowed to call CreateAccessKey is irrelevant to alarm triggering because CloudTrail logs every API call, including calls that are denied by IAM policies. The metric filter pattern typically matches on the eventName field, so an AccessDenied error still produces an event with eventName CreateAccessKey and increments the metric. A lack of IAM permissions would cause the user's request to fail, but it cannot explain why CloudWatch fails to alarm; that is a separate authorization concern, not a monitoring pipeline concern.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.