SCS-C02 Threat Detection and Incident Response Practice Question
A company uses AWS CloudTrail to log all API calls. The security team wants to be alerted when an IAM user creates a new access key for another IAM user (an action that could indicate privilege escalation). What is the most effective way to detect this specific API call?
⚠ Common exam trap
It's easy for candidates to confuse AWS Config (which evaluates resource state) with CloudTrail (which records API actions), leading them to choose Option B, but Config cannot detect the API call itself—only the resulting configuration change, which may be too late or ambiguous.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Amazon CloudWatch Events rule that matches the 'iam:CreateAccessKey' API call and sends a notification to an SNS topic.
Amazon CloudWatch Events (now Amazon EventBridge) can be configured with a rule that matches the specific 'iam:CreateAccessKey' API call as it occurs. When this API call is made, CloudTrail delivers the event in near real-time to CloudWatch Events, which can then trigger an SNS topic to send an alert. This provides immediate, event-driven detection without the latency of scheduled queries or the overhead of custom rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Query AWS CloudTrail logs using Amazon Athena on a schedule.
Why it's wrong here
Querying CloudTrail logs with Athena on a schedule is a batch analysis approach, not a real-time alerting mechanism. Athena incurs per-query scan costs and requires S3 log delivery to complete before queries run, so a scheduled query can only identify access key creations minutes or hours after the fact. It also returns results to a dashboard or a follow-up script rather than proactively pushing a notification, which fails the requirement for immediate security alerting.
- ✗
Use AWS Config to create a custom rule that checks for changes to IAM users.
Why it's wrong here
AWS Config custom rules are designed to evaluate resource configurations, such as whether an IAM user has MFA or an attached policy, not to process individual CloudTrail API events. While Config can detect that an IAM user resource changed, it does not capture the event context—who made the CreateAccessKey call, from what source IP, or with which user agent—and evaluations run on a periodic or configuration-change trigger that introduces delay. Therefore, Config cannot provide a real-time, event-specific alert for the CreateAccessKey API action.
- ✓
Create an Amazon CloudWatch Events rule that matches the 'iam:CreateAccessKey' API call and sends a notification to an SNS topic.
Why this is correct
A CloudWatch Events rule (now Amazon EventBridge) can use an event pattern matching the iam:CreateAccessKey API call emitted by CloudTrail, specifying source as 'aws.iam' and eventName as 'CreateAccessKey'. The rule can invoke an SNS topic within seconds of the API call, allowing immediate email, SMS, or Lambda-based notifications. This is the only option that is event-driven, real-time, and precisely scoped to the security-sensitive action of creating an IAM access key.
- ✗
Enable Amazon GuardDuty and look for the 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' finding.
Why it's wrong here
GuardDuty's UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration finding detects when temporary credentials from an EC2 instance are exfiltrated and used from outside AWS, not when a user deliberately creates a new IAM access key. GuardDuty relies on anomaly detection, VPC flow logs, DNS logs, and threat intelligence rather than matching a specific CloudTrail API event name. Findings can also take tens of minutes to hours to appear, so this option is unsuitable for near-real-time notification on CreateAccessKey.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.