Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company uses AWS CloudTrail to log all API calls. The security team wants to ensure that any attempt to disable CloudTrail logging is detected and alerted within minutes. Which solution should they implement?

⚠ Common exam trap

Candidates often confuse AWS Config's periodic evaluation with real-time CloudWatch alarm capabilities, or mistakenly think GuardDuty's threat detection includes specific API-level alerts for CloudTrail disablement, when in fact GuardDuty does not generate findings for these specific management events by default.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a CloudWatch metric filter on CloudTrail logs for StopLogging or DeleteTrail events and set an alarm.

CloudTrail logs API calls like `StopLogging` and `DeleteTrail` to CloudWatch Logs. By creating a metric filter on these specific event names and setting a CloudWatch alarm, the security team can receive near-real-time alerts within minutes of any attempt to disable CloudTrail logging, meeting the detection requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a CloudWatch metric filter on CloudTrail logs for StopLogging or DeleteTrail events and set an alarm.

    Why this is correct

    A CloudWatch metric filter can inspect CloudTrail events as they are streamed to a CloudWatch Logs log group and match the eventName field for StopLogging or DeleteTrail API calls. When the filter's metric value changes, a CloudWatch alarm triggers immediately, enabling a real-time response before the trail is completely stopped or deleted. This approach directly monitors the management events that disable auditing, without relying on secondary indicators like object delivery. It also supports optional SNS notifications and Lambda actions for automated remediation.

  • ✗

    Use Amazon GuardDuty to monitor for disablement events.

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that uses machine learning and integrated threat intelligence to identify anomalous behavior and compromised credentials. It does not have a specific finding type for CloudTrail StopLogging or DeleteTrail events, and it does not continuously monitor the configuration state of CloudTrail trails. While GuardDuty may detect an attacker after they perform malicious actions, it cannot provide real-time, purpose-built alerts for the act of disabling CloudTrail logging. Therefore, it is not the appropriate tool for this exact requirement.

  • ✗

    Create an AWS Config rule to detect when CloudTrail is disabled.

    Why it's wrong here

    An AWS Config rule can evaluate whether a CloudTrail trail exists and is enabled, typically using the managed rule cloudtrail-enabled, but it operates on resource configuration snapshots and change notifications, not on the API calls themselves. Even if the rule detects that CloudTrail is disabled, it does so after the fact and may only flag the resource's noncompliance, not the identity or details of the StopLogging/DeleteTrail action. AWS Config also cannot capture the event in real time because evaluations are triggered periodically or on configuration changes, so it lacks the immediacy of a CloudWatch alarm tied to the log stream. For detecting the actual API call as it happens, a CloudWatch metric filter is required.

  • ✗

    Configure S3 event notifications on the CloudTrail bucket.

    Why it's wrong here

    Configuring S3 event notifications on the CloudTrail log bucket would only trigger when CloudTrail delivers a new log file object to the bucket, such as on PutObject requests. If an attacker calls StopLogging or DeleteTrail, no new log files are generated, so no notification is sent, leaving the disablement undetected. S3 event notifications are designed for object-level lifecycle and processing workflows, not for auditing the CloudTrail API itself. Additionally, the notification would not contain any information about the API call that stopped logging; it would simply indicate that a log file was written, which provides no security signal for this scenario.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.