SCS-C02 Security Logging and Monitoring Practice Question
A security team needs to be alerted when an IAM user generates a console login failure. Which combination of AWS services should be used to meet this requirement?
⚠ Common exam trap
A common mix-up: candidates think CloudTrail alone is sufficient for alerting, but CloudTrail only logs events; it requires integration with CloudWatch Logs and Alarms to generate notifications, and options like GuardDuty or Config are often mistakenly chosen because they sound security-related but do not directly address the specific login failure alerting requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudTrail, Amazon CloudWatch Logs, and CloudWatch Alarms
CloudTrail captures IAM console login failures as CloudTrail events, which can be streamed to CloudWatch Logs. A CloudWatch Alarm can then be configured to trigger on a metric filter that matches the specific 'ConsoleLogin' event with a 'Failure' status, enabling real-time alerting via Amazon SNS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CloudTrail and Amazon S3
Why it's wrong here
CloudTrail can deliver logs to an S3 bucket, but S3 is an object storage service with no native stream-processing or alerting capability. While you could configure S3 event notifications to invoke a Lambda function that parses CloudTrail logs, the logs are typically delivered in 5-minute increments, so this is not a real-time alerting architecture, and S3 itself cannot filter for IAM login failures.
- ✓
CloudTrail, Amazon CloudWatch Logs, and CloudWatch Alarms
Why this is correct
The correct architecture is CloudTrail for recording console login events, CloudWatch Logs as the destination for those CloudTrail events, and a CloudWatch Logs metric filter that looks for IAM console sign-in failures (e.g., MFA denied or incorrect password). The metric filter increments a CloudWatch metric, and a CloudWatch Alarm on that metric triggers an Amazon SNS notification, delivering a near-real-time alert when a defined threshold (like 1 failure) is breached.
- ✗
AWS Config and Amazon SNS
Why it's wrong here
AWS Config records resource configuration changes but does not capture real-time authentication events such as console login failures, which are logged by AWS CloudTrail. This option is tempting because AWS Config can trigger SNS notifications for noncompliant resources, making it seem suitable for alerting; it would be correct for detecting drift in IAM policies or resource configurations, not for monitoring authentication failures.
- ✗
Amazon GuardDuty and AWS Lambda
Why it's wrong here
GuardDuty does not continuously monitor for routine IAM console login failures; it uses anomaly detection and threat intelligence on VPC Flow Logs, DNS logs, and selected CloudTrail events for suspicious activity like credentialed access or brute-force patterns. Adding Lambda would be unnecessary for a simple login failure alert because GuardDuty is not designed to emit an event for every single failed IAM console login, and Lambda alone would not provide the required alerting without additional CloudWatch configuration.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.