SCS-C02 Threat Detection and Incident Response Practice Question
A security team wants to detect and alert on API calls that create or modify IAM roles in their AWS account. Which AWS service can be used to create a metric filter and alarm for these specific CloudTrail events?
⚠ Common exam trap
Candidates often confuse CloudTrail's logging capability with CloudWatch Logs' metric and alarm features, assuming CloudTrail itself can create alarms, when in reality CloudTrail only delivers logs and CloudWatch Logs provides the filtering and alerting mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Logs
Amazon CloudWatch Logs can create metric filters on CloudTrail log data to detect specific API calls, such as CreateRole or UpdateAssumeRolePolicy. These metric filters can then trigger CloudWatch alarms for real-time notification. CloudTrail delivers logs to CloudWatch Logs, but the metric filter and alarm capabilities reside in CloudWatch Logs, not in CloudTrail itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that uses threat intelligence, anomaly detection, and machine learning to analyze CloudTrail management events, VPC flow logs, and DNS logs. However, it does not support custom metric filters on CloudTrail event patterns, nor does it allow you to define alarm thresholds for specific API call sequences. GuardDuty identifies security threats like compromised credentials or malicious activity, but you cannot configure it to alert on an arbitrary, user-defined API call pattern. Therefore it does not meet the requirement for custom detection and alerting.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is the service that records API activity by capturing events and delivering them to an S3 bucket or CloudWatch Logs, but it has no native alerting capability. CloudTrail does not evaluate event patterns, trigger alarms, or send notifications based on the content of API calls; it only provides the log data. To detect and alert on specific API calls, you must pair CloudTrail with another service, such as CloudWatch Logs metric filters + alarms or Amazon EventBridge rules. By itself, CloudTrail is just the source of the event record, not the detection mechanism.
- ✓
Amazon CloudWatch Logs
Why this is correct
Amazon CloudWatch Logs can ingest CloudTrail events when a trail is configured to send events to CloudWatch Logs, and then you can create a metric filter that uses pattern matching to identify specific API calls such as 'StopInstances' or 'DeleteBucket'. The metric filter counts occurrences of matching events in near-real time, and a CloudWatch alarm on that metric can trigger an SNS notification or other action. This is a native, fully managed solution for custom API call detection and alerting, directly satisfying the security team's requirement.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service that records configuration changes to AWS resources and evaluates those configurations against rules to assess compliance. It does not process or analyze CloudTrail API call events, nor does it have features for filtering event logs or creating alarms based on API activity. Config's focus is on the state and history of resource configurations (e.g., whether an S3 bucket is public), not on operational event streams. Therefore it is unsuitable for detecting and alerting on specific API calls as described.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.