A security engineer is designing a system to detect and respond to IAM policy changes that could grant excessive permissions. The solution must alert within minutes of the change and automatically revert the change if it violates a predefined baseline. Which combination of services should the engineer use?
CloudTrail continuously streams API activity from the account, and a CloudWatch Events rule can match specific IAM actions (e.g., PutUserPolicy, AttachUserPolicy) in real time. The rule triggers a Lambda function, which can immediately respond by removing the policy, restoring a backup, or alerting security personnel. This is a native, serverless, event-driven architecture that satisfies both detection and automated remediation.
Why this answer
AWS CloudTrail logs IAM policy changes. Amazon CloudWatch Events (now EventBridge) can match specific API calls (e.g., PutRolePolicy) and trigger an AWS Lambda function within minutes. The Lambda function can evaluate the change against a baseline and automatically revert it if it violates the policy, providing both detection and remediation.
Exam trap
SCS-C02 often tests the misconception that AWS Config can automatically remediate without additional services, or that CloudTrail alone can trigger actions, ignoring the need for EventBridge and Lambda.
How to eliminate wrong answers
Option A is wrong because CloudTrail and S3 only store logs; they do not provide real-time alerting or automated remediation. Option C is wrong because AWS Config can detect changes but does not automatically revert them; Systems Manager can automate but requires additional setup and is not event-driven in the same way. Option D is wrong because IAM Access Analyzer identifies overly permissive policies but does not automatically revert changes; Lambda alone lacks the event trigger from CloudTrail.