SCS-C02 Security Logging and Monitoring Practice Question
A security engineer needs to monitor AWS API calls for potential unauthorized access. The engineer wants to be alerted when a specific IAM user performs a high-risk action like deleting a CloudTrail trail. What is the MOST efficient way to achieve this?
⚠ Common exam trap
Watch out — candidates often default to CloudTrail + CloudWatch Logs + metric filters (Option A) because it's a common pattern, but they overlook that CloudWatch Events provides a simpler, lower-latency, and more cost-effective solution for real-time alerting on specific API calls without the overhead of log ingestion and metric evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudWatch Events rule that matches the API call and sends an SNS notification.
CloudWatch Events (now part of Amazon EventBridge) can directly capture AWS API calls from CloudTrail in near real-time. By creating a rule that matches the specific API call (e.g., `DeleteTrail`) from a specific IAM user, you can trigger an SNS notification instantly without the latency or cost of log shipping, metric filters, or periodic queries. This is the most efficient method for real-time alerting on specific API actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure CloudTrail to send logs to CloudWatch Logs and create a metric filter with an alarm.
Why it's wrong here
This approach is valid but suboptimal. It requires enabling CloudTrail to send logs to CloudWatch Logs, then creating a metric filter to count the API call and an alarm to trigger on that metric. The added pipeline introduces latency and operational overhead, whereas a CloudWatch Events rule reacts directly and immediately to the event.
- ✗
Enable VPC Flow Logs and analyze with Elasticsearch.
Why it's wrong here
VPC Flow Logs record IP traffic at network interfaces, such as instances and ENIs, but they do not capture AWS management API calls. API calls like the one to be monitored are control-plane operations that appear in CloudTrail, not in flow logs. Analyzing flow logs with Elasticsearch would only reveal network connections, not user identities, actions, or parameters, so this option misses the intended activity entirely.
- ✗
Use Amazon Athena to query CloudTrail logs daily for the action.
Why it's wrong here
Amazon Athena can run SQL queries over CloudTrail logs stored in S3, but a daily scheduled query means you would only discover the suspicious API call up to 24 hours after it occurs. This is not real-time monitoring and does not proactively alert. Furthermore, Athena queries are manually triggered or scheduled with additional services, adding complexity and delay compared to an event-driven rule.
- ✗
Enable Amazon GuardDuty with a custom threat list.
Why it's wrong here
Amazon GuardDuty analyzes telemetry such as VPC Flow Logs, DNS logs, and CloudTrail management events for known threat indicators, but it does not support custom rules to flag a specific API action performed by a specific IAM user. A custom threat list is an allow/deny list of IP addresses, not a mechanism for singling out API call patterns. Therefore, GuardDuty cannot fulfill the requirement to monitor for a particular API call.
- ✓
Create a CloudWatch Events rule that matches the API call and sends an SNS notification.
Why this is correct
A CloudWatch Events rule (now Amazon EventBridge) can define an event pattern that matches the exact API call, because CloudTrail delivers all AWS API events as CloudWatch Events in near real-time. When the event matches, the rule triggers an SNS topic to send a notification. This provides immediate, event-driven alerting without the delay of log aggregation, querying, or metric filters.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.