Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security analyst needs to receive an alert when an IAM user attempts to perform an action they are not authorized to perform. Which AWS service can be used to monitor and alert on such authorization failures?

⚠ Common exam trap

Many candidates confuse IAM Access Analyzer's 'findings' about external access with real-time monitoring of authorization failures, or they think AWS Config's compliance rules can alert on API denials, but neither service processes CloudTrail API logs for this purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail with CloudWatch metric filter and alarm

AWS CloudTrail logs all API calls made by IAM users, including authorization failures (e.g., AccessDenied errors). By creating a CloudWatch metric filter on CloudTrail logs for specific error codes like 'AccessDenied' or 'UnauthorizedOperation', you can trigger a CloudWatch alarm to send notifications via SNS. This is the standard AWS approach for monitoring and alerting on unauthorized actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Organizations SCPs

    Why it's wrong here

    AWS Organizations service control policies act as guardrails that cap the maximum effective permissions a principal can receive via IAM, but they do not emit alerts, log events, or detect denied actions. SCPs are purely preventive controls evaluated when a request is made, so they provide no visibility into failed IAM activity. To generate alerts, you need an audit trail such as CloudTrail combined with CloudWatch monitoring, not the SCP mechanism itself.

  • ✓

    AWS CloudTrail with CloudWatch metric filter and alarm

    Why this is correct

    CloudTrail records every IAM API call as an event, including AccessDenied responses, and can deliver those events to CloudWatch Logs. A CloudWatch Logs metric filter can count occurrences of a specific pattern, such as an IAM-issued authorization failure, and a CloudWatch alarm can then trigger an Amazon SNS notification. This combination provides near-real-time detective monitoring without inserting latency into the original IAM request.

  • ✗

    AWS IAM Access Analyzer

    Why it's wrong here

    IAM Access Analyzer inspects resource policies once they exist and reports findings when those policies grant access to external principals, such as public or cross-account access to roles, S3 buckets, or KMS keys. It does not examine the live call stream or capture IAM authorization failures, so it cannot alert on an individual user's denied API operations. Its findings are proactive security notifications about policy design, not operational alerts about runtime attempts.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config continuously records configuration changes for supported resources, including IAM policies and roles, and evaluates them against managed or custom rules for compliance. It does not record the API calls that invoked those changes, and it has no concept of a denied IAM operation or a user's failed attempt. Since configuration tracking is a change-management function, it cannot be used to alert on unauthorized IAM use without a separate API activity source like CloudTrail.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.