SCS-C02 Threat Detection and Incident Response Practice Question
A security team is using AWS CloudTrail and Amazon CloudWatch Logs to monitor for unauthorized API calls. They want to receive an alert when an API call is made with an access key that has been reported as compromised. They have configured CloudTrail to send logs to CloudWatch Logs. What should they do next to achieve this?
⚠ Common exam trap
The trap here is assuming GuardDuty or CloudTrail Insights can monitor for a specific user-defined access key ID, when they do not support such custom matching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudWatch Logs metric filter that matches the access key ID in the CloudTrail logs, and create a CloudWatch alarm that publishes to an SNS topic.
The most efficient and real-time method is to create a CloudWatch Logs metric filter that matches the compromised access key ID in the CloudTrail logs. When the filter matches, it increments a custom metric. A CloudWatch alarm on that metric can then publish to an SNS topic, alerting the team. This leverages the existing log delivery and requires no custom code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an AWS Lambda function that periodically queries CloudTrail event history for the access key ID and sends an alert via Amazon SES.
Why it's wrong here
While a Lambda function could query CloudTrail, this is not real-time and requires custom code and scheduling. It also does not leverage the existing CloudWatch Logs integration. This approach is less efficient and more complex than using a metric filter and alarm. It may also miss events due to the 90-day limit and polling delays.
- ✓
Create a CloudWatch Logs metric filter that matches the access key ID in the CloudTrail logs, and create a CloudWatch alarm that publishes to an SNS topic.
Why this is correct
CloudWatch Logs metric filters can search for specific terms, such as the compromised access key ID, in the log data. When the filter matches, it increments a metric. A CloudWatch alarm on that metric can trigger an SNS notification, providing the desired alert. This is the standard method for alerting on specific log patterns.
- ✗
Use Amazon GuardDuty to monitor for the compromised access key and configure it to send findings to an SNS topic.
Why it's wrong here
GuardDuty can detect some compromised credential usage through threat intelligence, but it does not allow you to specify a particular access key ID to monitor. It generates findings based on its own intelligence and anomaly detection. It cannot be configured to alert solely on the use of a specific known-compromised key.
- ✗
Enable AWS CloudTrail Insights to automatically detect the compromised access key and send an alert.
Why it's wrong here
CloudTrail Insights detects unusual operational activity, such as spikes in API call volume or error rates, but it does not specifically monitor for a known compromised access key ID. It uses machine learning to establish baselines and identify anomalies, not to match specific values. It would not reliably alert on the use of a particular access key.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.