SCS-C02 Security Logging and Monitoring Practice Question
A company wants to detect and alert on unauthorized API calls in their AWS account. Which AWS service can provide real-time notifications when specific API calls are made?
⚠ Common exam trap
Many exam-takers confuse AWS Config's configuration change detection with real-time API call monitoring, but Config evaluates resource state changes at intervals or on configuration changes, not the API calls themselves, whereas EventBridge provides immediate, event-driven notification of specific API actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Events (EventBridge)
Amazon CloudWatch Events (now part of Amazon EventBridge) can capture real-time API calls made to AWS services by using a rule that matches specific API calls via CloudTrail integration. When a matching API call occurs, EventBridge can trigger a target such as an SNS topic or Lambda function to send a notification, enabling immediate alerting on unauthorized API calls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config continuously records and evaluates AWS resource configuration changes and relationships, not event-level API activity. Although it can leverage CloudTrail data to detect configuration drift, it is designed for configuration history and compliance rules, so it cannot directly alert on unauthorized API calls such as a denied IAM Action or a failed DeleteBucket attempt. For API-call-specific detection, you need event-driven processing rather than a configuration recorder.
- ✓
Amazon CloudWatch Events (EventBridge)
Why this is correct
Amazon EventBridge (formerly CloudTrail Events integration within CloudWatch Events) is the appropriate real-time service because it can consume CloudTrail API-call events and pattern-match on fields like eventName, userIdentity, errorCode, and sourceIPAddress. You can create a rule with a custom event pattern—for example, source: 'aws.cloudtrail' and eventName: 'DeleteBucket'—and route matching events to SNS, Lambda, or CloudWatch Logs to trigger alerts. This gives near-instant, event-driven detection of unauthorized API attempts, including filtered access-denied events.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty is a security analytics service that uses machine learning, anomaly detection, and threat intelligence feeds to generate findings about suspicious behavior, such as compromised credentials or unusual API patterns. It is not a generic alerting mechanism for all API calls, and you cannot define a simple rule to alert on a specific unauthorized API call directly in GuardDuty. Its findings are useful after the fact for investigating threats, but they do not replace a CloudTrail-driven EventBridge rule for precise, real-time API-call monitoring.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor is an advisory service that inspects your account against best practices across cost optimization, security, fault tolerance, performance, and service limits, providing a dashboard and exportable reports. It does not observe the live stream of API calls in real time, so it cannot detect or alert on unauthorized API activity as it happens. Its security checks, such as S3 bucket permissions or IAM usage, evaluate point-in-time configuration states rather than monitoring event activity.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.