Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company has an Amazon S3 bucket that stores critical data. The security team wants to be notified whenever an object in the bucket is deleted. Which solution should the SysOps administrator implement?

⚠ Common exam trap

It's easy for candidates to assume S3 event notifications are sufficient for all object operations, but they do not provide detailed API call information or integrate natively with CloudWatch Events for centralized monitoring and alerting. CloudTrail data events capture every DeleteObject API call with full request details, enabling robust alerting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable CloudTrail data events for the S3 bucket, create a CloudWatch Events rule for 'DeleteObject' API calls, and send notifications via SNS.

It uses CloudTrail data events to capture 'DeleteObject' API calls specifically for the S3 bucket, then routes those events via CloudWatch Events to an SNS topic for notification. This provides a reliable, real-time notification mechanism for object deletions without requiring custom code or post-hoc analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an S3 event notification for 's3:ObjectRemoved:*' events to trigger an AWS Lambda function that sends an email.

    Why it's wrong here

    S3 event notifications do capture object removal events, including versioned deletions (via s3:ObjectRemoved:DeleteMarkerCreated). However, this solution requires custom Lambda code to send emails and does not integrate directly with CloudWatch Events for centralized alerting and auditing. More importantly, it lacks the identity information (who deleted the object) that CloudTrail provides, which is crucial for security teams.

  • ✓

    Enable CloudTrail data events for the S3 bucket, create a CloudWatch Events rule for 'DeleteObject' API calls, and send notifications via SNS.

    Why this is correct

    CloudTrail data events are the only option here that records object-level API calls (DeleteObject, DeleteObjects) in the S3 bucket, and each event includes the caller's IAM identity, source IP, user agent, and timestamp. By configuring a CloudWatch Events rule that matches the s3.amazonaws.com service with the DeleteObject event name, you get near-real-time alerts delivered through an SNS topic. This provides both a complete audit trail for forensic investigation and immediate operational notification, satisfying the requirement to know who deleted what, when, and from where.

  • ✗

    Use AWS Config to monitor S3 bucket resources and trigger an SNS notification on configuration changes.

    Why it's wrong here

    AWS Config evaluates resource configurations (e.g., bucket policies, encryption settings, versioning, lifecycle rules) and records configuration changes; it does not see object-level actions such as DeleteObject calls. While it can send SNS on configuration changes, those changes are unrelated to the deletion of objects and would not trigger on a simple object deletion unless the bucket configuration itself changes. This option fails to meet the core requirement of alerting on data-plane delete operations and lacks the identity context needed for security review.

  • ✗

    Enable S3 server access logs and use Amazon Athena to query for delete events, then send notifications.

    Why it's wrong here

    S3 server access logs are delivered on a best-effort basis with delays that can range from minutes to hours, and they are not designed for real-time alerting—they are for periodic analysis and troubleshooting. You would have to write Athena queries to filter log records for DELETE operations and then build a separate workflow to parse results and send SNS notifications, making the solution both reactive and operationally complex. Critically, server access logs do not include a true timestamp for near-real-time alerting nor do they provide the same level of identity information as CloudTrail data events, and they are not integrated with CloudWatch Events.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.