Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to monitor for unauthorized changes to IAM roles and policies in an AWS account. The engineer wants to receive an email notification whenever an IAM policy is attached to a role. Which AWS services should be combined to achieve this?

⚠ Common exam trap

Test-takers frequently confuse AWS Config's compliance evaluation and SNS notifications with real-time event-driven monitoring, but Config evaluates resources on a periodic or change-triggered basis rather than capturing every API call instantly like CloudTrail and EventBridge do.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail and Amazon CloudWatch Events (Amazon EventBridge)

AWS CloudTrail logs all API calls, including AttachRolePolicy, and CloudWatch Events (EventBridge) can filter for that specific event and trigger an action such as sending an email via SNS. This combination allows real-time monitoring and notification for unauthorized IAM policy attachments to roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty and Amazon Simple Email Service (SES)

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that ingests CloudTrail, VPC Flow, and DNS logs to identify malicious activity, but it cannot be configured to monitor for a specific unauthorized API change in real time; it only surfaces findings based on known threat intelligence. Amazon SES serves solely as an email-sending service and does not add event filtering or alerting logic. Therefore this combination lacks the necessary event pattern matching and direct API-call visibility.

  • ✓

    AWS CloudTrail and Amazon CloudWatch Events (Amazon EventBridge)

    Why this is correct

    AWS CloudTrail is the correct source because it records management events such as an IAM policy modification, capturing the requesting principal, event time, and source IP. Amazon CloudWatch Events (now Amazon EventBridge) can define an event pattern that matches the specific CloudTrail event name and source, then targets an SNS topic to notify the security team. Together they provide near-real-time, API-level monitoring and alerting for unauthorized changes.

  • ✗

    AWS Config and Amazon Simple Notification Service (SNS)

    Why it's wrong here

    AWS Config evaluates resource configurations and tracks configuration history, but it does not identify which IAM API call caused the change, so the security engineer cannot attribute the unauthorized action to a specific principal. Config can publish configuration change notifications to Amazon SNS, but those continuous compliance evaluations are state-based and delayed, not designed for event-driven, API-specific detection. This makes the combination less appropriate than CloudTrail with EventBridge.

  • ✗

    Amazon Inspector and Amazon CloudWatch Logs

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure; it has no visibility into IAM users, roles, or policy changes. Amazon CloudWatch Logs can store and alarm on log data, but Inspector does not produce CloudTrail-like API activity logs for IAM. Consequently, this combination cannot detect or alert on unauthorized IAM modifications.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.