Courseiva

Real-Time Alerting for Security Group Modifications with EventBridge

A security engineer needs to be alerted when an IAM user attempts to modify an S3 bucket policy. Which method is the MOST efficient?

⚠ Common exam trap

The trap here is that candidates often overcomplicate the solution by choosing log-based methods (A or D) or evaluation-based methods (B), missing that CloudWatch Events provides the simplest and most direct real-time alerting for specific API calls without additional overhead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Amazon CloudWatch Events rule that matches the PutBucketPolicy API call and triggers an SNS notification

Amazon CloudWatch Events (now Amazon EventBridge) can directly capture the PutBucketPolicy API call as a real-time event and trigger an SNS notification without any additional compute or polling. This is the most efficient method as it requires no log parsing, no custom code, and no additional infrastructure, providing immediate alerting with minimal overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable VPC Flow Logs and analyze for S3 API traffic

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata—source and destination addresses, ports, and protocols—at the network interface level. They do not contain the S3 API operation name (such as PutBucketPolicy) or the request body, so you cannot identify which management action occurred. Even with a VPC endpoint, flow logs would only show TLS connections to S3, not the API calls themselves.

  • ✗

    Configure an AWS Config rule to detect changes and invoke a Lambda function

    Why it's wrong here

    AWS Config records and evaluates resource configuration changes, not individual IAM or API calls. A Config rule with Lambda remediation could react to a bucket policy becoming noncompliant, but it runs on a periodic or configuration-change basis and is not designed for immediate per-event alerting. The requirement is to alert on the PutBucketPolicy call itself, which only a CloudTrail/EventBridge pattern can match.

  • ✓

    Create an Amazon CloudWatch Events rule that matches the PutBucketPolicy API call and triggers an SNS notification

    Why this is correct

    Create an Amazon CloudWatch Events (now Amazon EventBridge) rule with an event pattern matching the `detail-type` of `AWS API Call via CloudTrail`, the `eventSource` as `s3.amazonaws.com`, and `eventName` as `PutBucketPolicy`. When CloudTrail logs that IAM API call, the rule triggers an SNS topic to notify the security engineer in near real time. This is the native AWS approach for reacting to control-plane actions.

  • ✗

    Enable S3 server access logs and parse them for PutBucketPolicy entries

    Why it's wrong here

    S3 server access logs record object-level requests such as GET, PUT, and DELETE on bucket objects; they do not include management-plane API calls like PutBucketPolicy. These logs are delivered in batches to a destination bucket, making them suitable for access auditing rather than immediate alerting. The requested action affects the bucket's configuration, so it appears only in CloudTrail, not in server access logs.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS CloudTrail to log all API calls. The security team needs to be alerted when an IAM user creates a new access key. Which approach is most efficient?

medium
  • A.Enable AWS Config managed rule to detect access key creation and trigger an SNS notification.
  • ✓ B.Create a CloudWatch Events rule that matches the CreateAccessKey event and targets an SNS topic.
  • C.Use CloudWatch Logs Insights to run a query every minute on CloudTrail logs and send results to SNS.
  • D.Configure CloudTrail to send logs to an S3 bucket and enable S3 event notifications to an SNS topic.

Why B: CloudWatch Events (now part of Amazon EventBridge) can directly match the CreateAccessKey API call from AWS CloudTrail in real time and trigger an SNS notification. This approach is the most efficient as it requires no polling, no additional infrastructure, and provides immediate alerting with minimal latency.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.