SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company has enabled AWS CloudTrail in all regions and is logging to an S3 bucket. The security team needs to be alerted within minutes if any IAM user creates a new access key. What is the MOST efficient way to achieve this?
⚠ Common exam trap
Many candidates choose S3 event notifications (Option A) because they think it's the simplest, but they overlook the built-in CloudWatch Logs integration which provides faster, more reliable, and fully managed alerting without custom code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure CloudTrail to send logs to CloudWatch Logs. Create a metric filter for the IAM event 'CreateAccessKey' and set a CloudWatch alarm that sends an SNS notification.
CloudTrail can be configured to deliver events to CloudWatch Logs, where a metric filter can be created to match the 'CreateAccessKey' event. A CloudWatch alarm based on that metric filter can then trigger an SNS notification within minutes, providing the most efficient and native AWS solution for real-time alerting without custom code or polling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable S3 event notifications on the CloudTrail bucket to trigger a Lambda function that parses logs and sends an alert.
Why it's wrong here
S3 event notifications are delivered asynchronously and can have noticeable delays, especially when CloudTrail delivers log files in batches, so they are not suitable for near-real-time security monitoring. Additionally, triggering a Lambda function for every CloudTrail log object would require parsing all logs to find the rare CreateAccessKey event, which is inefficient and may incur significant cost and processing time. A direct metric filter in CloudWatch Logs avoids both the delay and the need to parse irrelevant data.
- ✗
Use AWS Config rules to detect changes to IAM access keys and trigger an SNS notification.
Why it's wrong here
AWS Config evaluates resources periodically and on configuration changes, but it is not a real-time security event service; its evaluations can lag significantly, so you would not receive an alert immediately when a new access key is created. Moreover, IAM access keys are not a native AWS Config resource type with out-of-the-box rules, so you would need to create a custom rule using a Lambda function, which still introduces periodic delays and complexity. For time-sensitive alerts on CloudTrail events, a metric filter and alarm are the standard solution.
- ✓
Configure CloudTrail to send logs to CloudWatch Logs. Create a metric filter for the IAM event 'CreateAccessKey' and set a CloudWatch alarm that sends an SNS notification.
Why this is correct
CloudTrail can be configured to deliver all management events to a CloudWatch Logs log group in near-real-time, allowing you to analyze them with metric filters. By creating a metric filter that matches the event name "CreateAccessKey" and setting a CloudWatch alarm on the resulting metric, you get an SNS notification as soon as the event occurs, with minimal latency and no need for custom code or compute resources. This is the serverless best practice for security event monitoring on AWS.
- ✗
Run a script on an EC2 instance that polls CloudTrail API for new events every minute and sends alerts.
Why it's wrong here
Polling the CloudTrail LookupEvents API every minute from a custom EC2 script introduces up to 60 seconds of latency and is subject to API throttling, which can cause missed events if many calls are made. It also requires you to manage and pay for an always-on EC2 instance, including operating system patches and high availability, making it less reliable and more operationally complex than a fully managed, serverless solution. CloudTrail's LookupEvents API retrieves events asynchronously and may not reflect the event within the same minute, further delaying alerts.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.