Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company wants to monitor for suspicious IAM activity, such as a user creating access keys without authorization. Which THREE AWS services can be used together to detect and alert on this activity in real-time? (Choose THREE.)

⚠ Common exam trap

A common mix-up: candidates confuse Amazon Inspector or Trusted Advisor as security monitoring services, but they lack the capability to monitor real-time IAM API activity, which requires CloudTrail, CloudWatch Logs, and SNS working together.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Logs

Amazon CloudWatch Logs is correct because it can ingest and monitor log data from AWS CloudTrail in real-time. By creating a CloudWatch Logs metric filter on CloudTrail logs for events like CreateAccessKey, you can trigger an alarm that sends notifications via SNS when unauthorized access key creation occurs. This enables real-time detection and alerting for suspicious IAM activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    CloudWatch Logs is the service that turns CloudTrail log data into actionable alarms. By creating a metric filter on a log group for events such as CreateAccessKey or ConsoleLogin failures, you can define a CloudWatch alarm that evaluates the metric and triggers an SNS notification when the count exceeds a threshold. This makes CloudWatch Logs the central monitoring component for detecting suspicious IAM activity in near real time.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is an automated vulnerability management service that scans Amazon EC2 instances and container images for software vulnerabilities and unintended network exposure. It does not ingest IAM CloudTrail logs or evaluate identity-based events, so it cannot detect or alert on suspicious activities like the creation of a new access key. Therefore, it is not applicable to this IAM monitoring requirement.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the source of evidence for IAM activity, recording every API call such as CreateAccessKey, AttachUserPolicy, and console sign-in events, along with details like source IP address and user agent. It must be enabled on the account and can deliver event logs to an S3 bucket or CloudWatch Logs, where they can be filtered and monitored. While CloudTrail itself provides the raw audit trail, it is a necessary prerequisite for any solution that detects suspicious IAM behavior.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor provides best-practice recommendations in categories like cost optimization, performance, security, and fault tolerance, based on a static analysis of the account’s configuration. It may flag issues such as unused IAM credentials or overly permissive policies, but it does not continuously process API events in real time and cannot alert on specific suspicious IAM actions as they occur. Therefore, it is not the right tool for this real-time monitoring need.

  • ✓

    Amazon Simple Notification Service (SNS)

    Why this is correct

    Amazon SNS is the notification delivery service that publishes messages to subscribers, such as email addresses, SMS endpoints, or Lambda functions, when a CloudWatch alarm enters an ALARM state. It does not itself inspect IAM activity or generate alarms; instead, it completes the monitoring pipeline by fanning out alerts to the appropriate security team. In this scenario, SNS ensures that a suspicious IAM event triggers an immediate, actionable notification.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.