Real-Time Alerting for Security Group Modifications with EventBridge
A security engineer needs to be alerted when an IAM user attempts to modify an S3 bucket policy. Which method is the MOST efficient?
⚠ Common exam trap
The trap here is that candidates often overcomplicate the solution by choosing log-based methods (A or D) or evaluation-based methods (B), missing that CloudWatch Events provides the simplest and most direct real-time alerting for specific API calls without additional overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Amazon CloudWatch Events rule that matches the PutBucketPolicy API call and triggers an SNS notification
Amazon CloudWatch Events (now Amazon EventBridge) can directly capture the PutBucketPolicy API call as a real-time event and trigger an SNS notification without any additional compute or polling. This is the most efficient method as it requires no log parsing, no custom code, and no additional infrastructure, providing immediate alerting with minimal overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable VPC Flow Logs and analyze for S3 API traffic
Why it's wrong here
VPC Flow Logs capture IP traffic metadata—source and destination addresses, ports, and protocols—at the network interface level. They do not contain the S3 API operation name (such as PutBucketPolicy) or the request body, so you cannot identify which management action occurred. Even with a VPC endpoint, flow logs would only show TLS connections to S3, not the API calls themselves.
- ✗
Configure an AWS Config rule to detect changes and invoke a Lambda function
Why it's wrong here
AWS Config records and evaluates resource configuration changes, not individual IAM or API calls. A Config rule with Lambda remediation could react to a bucket policy becoming noncompliant, but it runs on a periodic or configuration-change basis and is not designed for immediate per-event alerting. The requirement is to alert on the PutBucketPolicy call itself, which only a CloudTrail/EventBridge pattern can match.
- ✓
Create an Amazon CloudWatch Events rule that matches the PutBucketPolicy API call and triggers an SNS notification
Why this is correct
Create an Amazon CloudWatch Events (now Amazon EventBridge) rule with an event pattern matching the `detail-type` of `AWS API Call via CloudTrail`, the `eventSource` as `s3.amazonaws.com`, and `eventName` as `PutBucketPolicy`. When CloudTrail logs that IAM API call, the rule triggers an SNS topic to notify the security engineer in near real time. This is the native AWS approach for reacting to control-plane actions.
- ✗
Enable S3 server access logs and parse them for PutBucketPolicy entries
Why it's wrong here
S3 server access logs record object-level requests such as GET, PUT, and DELETE on bucket objects; they do not include management-plane API calls like PutBucketPolicy. These logs are delivered in batches to a destination bucket, making them suitable for access auditing rather than immediate alerting. The requested action affects the bucket's configuration, so it appears only in CloudTrail, not in server access logs.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS CloudTrail to log all API calls. The security team needs to be alerted when an IAM user creates a new access key. Which approach is most efficient?
medium- A.Enable AWS Config managed rule to detect access key creation and trigger an SNS notification.
- ✓ B.Create a CloudWatch Events rule that matches the CreateAccessKey event and targets an SNS topic.
- C.Use CloudWatch Logs Insights to run a query every minute on CloudTrail logs and send results to SNS.
- D.Configure CloudTrail to send logs to an S3 bucket and enable S3 event notifications to an SNS topic.
Why B: CloudWatch Events (now part of Amazon EventBridge) can directly match the CreateAccessKey API call from AWS CloudTrail in real time and trigger an SNS notification. This approach is the most efficient as it requires no polling, no additional infrastructure, and provides immediate alerting with minimal latency.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.