Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security team needs to be alerted when an IAM user generates a console login failure. Which combination of AWS services should be used to meet this requirement?

⚠ Common exam trap

A common mix-up: candidates think CloudTrail alone is sufficient for alerting, but CloudTrail only logs events; it requires integration with CloudWatch Logs and Alarms to generate notifications, and options like GuardDuty or Config are often mistakenly chosen because they sound security-related but do not directly address the specific login failure alerting requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudTrail, Amazon CloudWatch Logs, and CloudWatch Alarms

CloudTrail captures IAM console login failures as CloudTrail events, which can be streamed to CloudWatch Logs. A CloudWatch Alarm can then be configured to trigger on a metric filter that matches the specific 'ConsoleLogin' event with a 'Failure' status, enabling real-time alerting via Amazon SNS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CloudTrail and Amazon S3

    Why it's wrong here

    CloudTrail can deliver logs to an S3 bucket, but S3 is an object storage service with no native stream-processing or alerting capability. While you could configure S3 event notifications to invoke a Lambda function that parses CloudTrail logs, the logs are typically delivered in 5-minute increments, so this is not a real-time alerting architecture, and S3 itself cannot filter for IAM login failures.

  • ✓

    CloudTrail, Amazon CloudWatch Logs, and CloudWatch Alarms

    Why this is correct

    The correct architecture is CloudTrail for recording console login events, CloudWatch Logs as the destination for those CloudTrail events, and a CloudWatch Logs metric filter that looks for IAM console sign-in failures (e.g., MFA denied or incorrect password). The metric filter increments a CloudWatch metric, and a CloudWatch Alarm on that metric triggers an Amazon SNS notification, delivering a near-real-time alert when a defined threshold (like 1 failure) is breached.

  • ✗

    AWS Config and Amazon SNS

    Why it's wrong here

    AWS Config records resource configuration changes but does not capture real-time authentication events such as console login failures, which are logged by AWS CloudTrail. This option is tempting because AWS Config can trigger SNS notifications for noncompliant resources, making it seem suitable for alerting; it would be correct for detecting drift in IAM policies or resource configurations, not for monitoring authentication failures.

  • ✗

    Amazon GuardDuty and AWS Lambda

    Why it's wrong here

    GuardDuty does not continuously monitor for routine IAM console login failures; it uses anomaly detection and threat intelligence on VPC Flow Logs, DNS logs, and selected CloudTrail events for suspicious activity like credentialed access or brute-force patterns. Adding Lambda would be unnecessary for a simple login failure alert because GuardDuty is not designed to emit an event for every single failed IAM console login, and Lambda alone would not provide the required alerting without additional CloudWatch configuration.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.