Monitor IAM User and Role Creation for Admin Privileges
A company's security team wants to receive alerts when an IAM user creates a new access key. Which AWS service can be used to monitor and notify on this specific API call?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail with Amazon CloudWatch Events
CloudTrail logs IAM CreateAccessKey events, and CloudWatch Events can trigger a notification. Option A is wrong because Trusted Advisor is for best practices. Option B is wrong because GuardDuty is for threat detection. Option D is wrong because AWS Config is for resource compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor is a service that performs checks against best practices and returns recommendations for cost, performance, security, and service limits. It does not process real-time API call streams, so it cannot trigger alerts when a specific IAM principal invokes a particular action. Its alerts are limited to check status changes (e.g., MFA on root account) and are not event-driven responses to individual API activities.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that aggregates metadata from CloudTrail events, VPC Flow Logs, and DNS logs, then applies anomaly detection and known threat intelligence to generate security findings. It does not expose a raw event rule engine for arbitrary API actions; it only surfaces high-signal findings after analysis, not an alert for each specific API call. To alert on a predetermined action, a CloudTrail-plus-EventBridge rule is required.
- ✓
AWS CloudTrail with Amazon CloudWatch Events
Why this is correct
AWS CloudTrail records every API call made by an IAM user or role, and delivering those trail events to Amazon CloudWatch Events (now EventBridge) enables custom rules that match exact API actions and principals. A rule can filter on eventName, userIdentity, and request parameters, then invoke an SNS topic to notify the security team in near real time. This is the only option that directly reacts to specific API activities rather than aggregate state or threats.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration and compliance service that tracks resource configuration changes over time and compares them to desired policy rules. It does not capture the API call that initiated the change, nor the identity of the caller, so it cannot alert on a specific IAM action. For example, Config knows a security group was updated, but it cannot tell you which user called AuthorizeSecurityGroupIngress.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.