Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company wants to detect and alert on unauthorized API calls in their AWS account. Which AWS service can provide real-time notifications when specific API calls are made?

⚠ Common exam trap

Many exam-takers confuse AWS Config's configuration change detection with real-time API call monitoring, but Config evaluates resource state changes at intervals or on configuration changes, not the API calls themselves, whereas EventBridge provides immediate, event-driven notification of specific API actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Events (EventBridge)

Amazon CloudWatch Events (now part of Amazon EventBridge) can capture real-time API calls made to AWS services by using a rule that matches specific API calls via CloudTrail integration. When a matching API call occurs, EventBridge can trigger a target such as an SNS topic or Lambda function to send a notification, enabling immediate alerting on unauthorized API calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config continuously records and evaluates AWS resource configuration changes and relationships, not event-level API activity. Although it can leverage CloudTrail data to detect configuration drift, it is designed for configuration history and compliance rules, so it cannot directly alert on unauthorized API calls such as a denied IAM Action or a failed DeleteBucket attempt. For API-call-specific detection, you need event-driven processing rather than a configuration recorder.

  • ✓

    Amazon CloudWatch Events (EventBridge)

    Why this is correct

    Amazon EventBridge (formerly CloudTrail Events integration within CloudWatch Events) is the appropriate real-time service because it can consume CloudTrail API-call events and pattern-match on fields like eventName, userIdentity, errorCode, and sourceIPAddress. You can create a rule with a custom event pattern—for example, source: 'aws.cloudtrail' and eventName: 'DeleteBucket'—and route matching events to SNS, Lambda, or CloudWatch Logs to trigger alerts. This gives near-instant, event-driven detection of unauthorized API attempts, including filtered access-denied events.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty is a security analytics service that uses machine learning, anomaly detection, and threat intelligence feeds to generate findings about suspicious behavior, such as compromised credentials or unusual API patterns. It is not a generic alerting mechanism for all API calls, and you cannot define a simple rule to alert on a specific unauthorized API call directly in GuardDuty. Its findings are useful after the fact for investigating threats, but they do not replace a CloudTrail-driven EventBridge rule for precise, real-time API-call monitoring.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is an advisory service that inspects your account against best practices across cost optimization, security, fault tolerance, performance, and service limits, providing a dashboard and exportable reports. It does not observe the live stream of API calls in real time, so it cannot detect or alert on unauthorized API activity as it happens. Its security checks, such as S3 bucket permissions or IAM usage, evaluate point-in-time configuration states rather than monitoring event activity.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.