How to Alert When an IAM User Creates an Access Key Without MFA
A company wants to receive an alert when an IAM user creates a new access key. Which AWS service should be used to trigger the alert?
⚠ Common exam trap
It's easy for candidates to confuse AWS CloudTrail with Amazon CloudWatch Logs, thinking CloudWatch Logs alone can trigger alerts, but CloudWatch Logs requires a metric filter and alarm setup, whereas CloudWatch Events directly matches API events without needing log ingestion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail and Amazon CloudWatch Events
AWS CloudTrail captures API calls made by or on behalf of an IAM user, including CreateAccessKey events. These events can be sent to Amazon CloudWatch Events (now part of Amazon EventBridge) using a rule that matches the specific API call, which then triggers an alert (e.g., via SNS or Lambda). This combination enables real-time monitoring and notification for security-sensitive actions like access key creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
CloudWatch Logs is a storage and aggregation service for log data, not an event-driven alerting mechanism. While CloudTrail can be configured to deliver management events to CloudWatch Logs, detecting a CreateAccessKey API call there would require a metric filter and a CloudWatch alarm to be built on top; the option does not include those components. Therefore, CloudWatch Logs alone cannot alert when an IAM user creates an access key.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a continuous security monitoring service that generates findings for suspicious or malicious activity using sources like VPC Flow Logs, DNS logs, and CloudTrail management events; it does not produce an alert for every normal IAM API action. Routine creation of an access key by an IAM user is a legitimate management operation, not a GuardDuty finding type, so GuardDuty will not trigger on it. Thus it fails the requirement of alerting on the specific CreateAccessKey event.
- ✓
AWS CloudTrail and Amazon CloudWatch Events
Why this is correct
AWS CloudTrail records every CreateAccessKey management event as a CloudTrail event containing the user identity, timestamp, source IP, and request details. Amazon CloudWatch Events (now Amazon EventBridge) can evaluate those CloudTrail events with an event pattern for eventName equal to CreateAccessKey and then route the matching event to an SNS topic or Lambda function to send the alert. Together, these two services provide the required real-time, event-driven notification.
- ✗
AWS Config
Why it's wrong here
AWS Config evaluates and records configuration changes to AWS resources, such as IAM users and their attached policies, but it does not capture discrete API actions like CreateAccessKey. It can use managed rules to check for compliance after the fact, for example whether access keys have been rotated, but that is not the same as receiving an alert at the moment an IAM user creates a key. Therefore, AWS Config cannot satisfy the stated requirement.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.