SCS-C02 Management and Security Governance Practice Question
Which TWO AWS services can be used to detect and alert on unauthorized API calls in real time?
⚠ Common exam trap
SCS-C02 often tests the distinction between detection services (GuardDuty, CloudWatch, EventBridge) and configuration/identity services (Config, IAM, KMS) — candidates may pick AWS Config thinking it alerts on API calls, but Config is for compliance evaluation, not real-time API monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Alarms
Amazon CloudWatch Alarms (A) is correct because you can create metric filters on CloudTrail log groups that match unauthorized API calls (e.g., AccessDenied or specific error codes), and the alarm triggers an SNS notification in near real time. Amazon EventBridge (C) is correct because it can receive CloudTrail management events, match patterns for unauthorized API activity (such as errorCode values), and route them to targets like SNS, Lambda, or SQS for immediate alerting. AWS KMS (B) is a key management service, not an API-call detection or alerting service. AWS IAM (D) controls authentication and authorization but does not itself detect or alert on unauthorized calls. AWS Config (E) evaluates resource configuration compliance and records configuration changes, not real-time API-call alerting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon CloudWatch Alarms
Why this is correct
CloudWatch Alarms work with CloudTrail by using metric filters that are applied to log groups containing CloudTrail events. When the metric filter detects a pattern such as a specific unauthorized API action or a spike in failed calls, the alarm shifts to ALARM and publishes to an SNS topic to alert operators. This threshold-based approach is one of the standard ways to turn historical CloudTrail logs into actionable alerts.
- ✗
AWS KMS
Why it's wrong here
AWS KMS is a key management service for creating, rotating, and controlling cryptographic keys, not a monitoring service. While KMS actions themselves are recorded in CloudTrail and KMS can be used to encrypt the CloudTrail log delivery, KMS does not evaluate API calls, emit metrics, or trigger alerts. It has no concept of detecting anomalous user activity and is therefore not a valid tool for this alerting use case.
- ✓
Amazon EventBridge
Why this is correct
Amazon EventBridge can consume CloudTrail events directly and evaluate them with rules that match exact fields such as event name, source, or user identity. A matching event triggers a target like Lambda, SNS, or Step Functions immediately, enabling real-time response to specific API calls. Unlike CloudWatch Alarms, which require a metric threshold, EventBridge reacts directly to the event payload, making it the other correct answer for detecting and alerting on API activity.
- ✗
AWS IAM
Why it's wrong here
AWS IAM defines who can access which AWS resources and what actions they are permitted to perform, but it does not monitor or analyze the API calls being made. IAM's last accessed information and access advisor are reporting features, not real-time alert generators. There is no IAM mechanism to watch CloudTrail events or emit an alarm when an unusual API operation occurs, so IAM cannot satisfy the detection requirement.
- ✗
AWS Config
Why it's wrong here
AWS Config continuously records and evaluates resource configuration changes using a configuration recorder and conformance rules. It can alert on changes to resource settings, such as a security group becoming too open, but it does not inspect individual API calls or provide real-time user-activity alerts. Since this question concerns detecting API actions, Config is not an appropriate service; it is designed for configuration drift assessment, not operation-level monitoring.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.