Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to monitor AWS account activity for suspicious API calls, such as disabling AWS CloudTrail or deleting an AWS Config recorder. The engineer wants to receive near-real-time alerts when such events occur. Which AWS service should the engineer use to meet these requirements?

⚠ Common exam trap

Test-takers frequently confuse threat detection services like GuardDuty with event-driven monitoring services like EventBridge.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Events (now Amazon EventBridge)

Amazon EventBridge (formerly CloudWatch Events) can monitor AWS CloudTrail logs for specific API calls and trigger alerts in near real-time. By creating an event rule that matches events like StopLogging or DeleteConfigurationRecorder, the engineer can receive immediate notifications. This directly meets the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon CloudWatch Events (now Amazon EventBridge)

    Why this is correct

    Amazon EventBridge can match events from AWS CloudTrail and trigger alerts via Amazon SNS or other targets. You can create a rule that matches specific API calls like StopLogging or DeleteConfigurationRecorder and sends a notification. This provides near-real-time alerts for the specified events.

  • ✗

    AWS CloudTrail Insights

    Why it's wrong here

    CloudTrail Insights helps identify unusual operational activity, such as spikes in API call volume, but it does not provide alerts for specific API calls like StopLogging or DeleteConfigurationRecorder. It is designed for anomaly detection, not for monitoring specific security-relevant events.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty is a threat detection service that analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to identify malicious activity. However, it does not specifically alert on configuration changes like disabling CloudTrail or deleting a Config recorder. It focuses on threat intelligence and anomaly detection.

  • ✗

    AWS Security Hub

    Why it's wrong here

    Security Hub aggregates and prioritizes security findings from multiple AWS services, but it does not directly monitor for specific API calls like disabling CloudTrail. It relies on other services to generate findings. It is not the primary service for real-time alerting on specific API events.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.