Courseiva

SCS-C02 Management and Security Governance Practice Question

Which TWO AWS services can be used to detect and alert on unauthorized API calls in real time?

⚠ Common exam trap

SCS-C02 often tests the distinction between detection services (GuardDuty, CloudWatch, EventBridge) and configuration/identity services (Config, IAM, KMS) — candidates may pick AWS Config thinking it alerts on API calls, but Config is for compliance evaluation, not real-time API monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Alarms

Amazon CloudWatch Alarms (A) is correct because you can create metric filters on CloudTrail log groups that match unauthorized API calls (e.g., AccessDenied or specific error codes), and the alarm triggers an SNS notification in near real time. Amazon EventBridge (C) is correct because it can receive CloudTrail management events, match patterns for unauthorized API activity (such as errorCode values), and route them to targets like SNS, Lambda, or SQS for immediate alerting. AWS KMS (B) is a key management service, not an API-call detection or alerting service. AWS IAM (D) controls authentication and authorization but does not itself detect or alert on unauthorized calls. AWS Config (E) evaluates resource configuration compliance and records configuration changes, not real-time API-call alerting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon CloudWatch Alarms

    Why this is correct

    CloudWatch Alarms work with CloudTrail by using metric filters that are applied to log groups containing CloudTrail events. When the metric filter detects a pattern such as a specific unauthorized API action or a spike in failed calls, the alarm shifts to ALARM and publishes to an SNS topic to alert operators. This threshold-based approach is one of the standard ways to turn historical CloudTrail logs into actionable alerts.

  • ✗

    AWS KMS

    Why it's wrong here

    AWS KMS is a key management service for creating, rotating, and controlling cryptographic keys, not a monitoring service. While KMS actions themselves are recorded in CloudTrail and KMS can be used to encrypt the CloudTrail log delivery, KMS does not evaluate API calls, emit metrics, or trigger alerts. It has no concept of detecting anomalous user activity and is therefore not a valid tool for this alerting use case.

  • ✓

    Amazon EventBridge

    Why this is correct

    Amazon EventBridge can consume CloudTrail events directly and evaluate them with rules that match exact fields such as event name, source, or user identity. A matching event triggers a target like Lambda, SNS, or Step Functions immediately, enabling real-time response to specific API calls. Unlike CloudWatch Alarms, which require a metric threshold, EventBridge reacts directly to the event payload, making it the other correct answer for detecting and alerting on API activity.

  • ✗

    AWS IAM

    Why it's wrong here

    AWS IAM defines who can access which AWS resources and what actions they are permitted to perform, but it does not monitor or analyze the API calls being made. IAM's last accessed information and access advisor are reporting features, not real-time alert generators. There is no IAM mechanism to watch CloudTrail events or emit an alarm when an unusual API operation occurs, so IAM cannot satisfy the detection requirement.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config continuously records and evaluates resource configuration changes using a configuration recorder and conformance rules. It can alert on changes to resource settings, such as a security group becoming too open, but it does not inspect individual API calls or provide real-time user-activity alerts. Since this question concerns detecting API actions, Config is not an appropriate service; it is designed for configuration drift assessment, not operation-level monitoring.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.