SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is reviewing AWS CloudTrail logs and notices a large number of DeleteBucket API calls from an unfamiliar IAM role. The engineer wants to automatically notify the security team when similar suspicious API activity occurs in the future. The notification must be sent within minutes and should include details such as the IAM role and the bucket name. Which solution should the engineer implement?
⚠ Common exam trap
The trap here is thinking that GuardDuty or CloudTrail Insights will alert on specific API calls, when they are designed for anomaly detection rather than exact event matching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Amazon EventBridge rule that matches AWS API calls via CloudTrail, filter for the DeleteBucket event, and route the event to an Amazon SNS topic that notifies the security team.
EventBridge can match CloudTrail management events and filter for specific API calls like DeleteBucket. Routing the event to SNS provides near real-time notification with the full event details, including the IAM role and bucket name. This is the most direct and low-latency solution for the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable CloudTrail Insights and configure an Amazon CloudWatch alarm on the Insights metric to send notifications via Amazon SNS.
Why it's wrong here
CloudTrail Insights detects unusual operational activity such as spikes in API call volume or error rates, but it does not automatically notify on specific API calls like DeleteBucket. Insights generates events that you can monitor, but the latency is typically longer than minutes, and it may not provide the specific bucket name in the notification. This option is not the most direct solution.
- ✗
Use Amazon GuardDuty to monitor for S3 bucket deletion activity and configure GuardDuty findings to send notifications via Amazon SNS.
Why it's wrong here
GuardDuty detects suspicious activity and threats, but it does not alert on every DeleteBucket API call. GuardDuty findings are generated for specific threat patterns, and a legitimate but suspicious deletion might not trigger a finding. Additionally, GuardDuty findings may not include the IAM role and bucket name in the same way as the raw CloudTrail event.
- ✗
Configure AWS Config to record configuration changes for S3 buckets and use an AWS Config rule to trigger an Amazon SNS notification when a bucket is deleted.
Why it's wrong here
AWS Config records configuration changes but does not directly detect API calls like DeleteBucket in real time. Config rules evaluate resource configurations periodically or on change, but they may not capture the IAM role that made the call, and the notification latency can be longer. This approach does not provide the required API-level detail within minutes.
- ✓
Create an Amazon EventBridge rule that matches AWS API calls via CloudTrail, filter for the DeleteBucket event, and route the event to an Amazon SNS topic that notifies the security team.
Why this is correct
EventBridge can match CloudTrail management events in near real time. By creating a rule that filters for DeleteBucket events, you can route the full event JSON to an SNS topic, which sends email or SMS to the security team. This provides rapid notification and includes details like the IAM role and bucket name in the event payload.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.