SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company is using AWS CloudTrail to log API activity in their account. The security team needs to be alerted when an IAM user creates a new access key. Which solution meets this requirement with the least operational overhead?
⚠ Common exam trap
Candidates often think CloudTrail itself can send email alerts (Option A) or that a security control like MFA (Option B) satisfies the alerting requirement, but neither provides the real-time notification specified in the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Amazon EventBridge rule that matches the CreateAccessKey event and targets an SNS topic.
Amazon EventBridge can directly match the `CreateAccessKey` API call from CloudTrail and trigger an SNS topic to send an alert in real time, requiring no custom code or polling. This provides the least operational overhead by using a fully managed, event-driven rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable CloudTrail email notifications for management events.
Why it's wrong here
CloudTrail is an audit logging service that records API activity and delivers event records to an S3 bucket or CloudWatch Logs; it does not have a built-in email notification mechanism. While CloudTrail can be integrated with SNS via CloudWatch alarms or EventBridge rules, that requires explicit configuration of those services, not a simple 'enable email notifications' setting. Therefore, this option is incorrect because it assumes a capability CloudTrail does not natively possess.
- ✗
Configure the IAM user's permissions to require MFA for access key creation.
Why it's wrong here
Configuring IAM permissions to require MFA for access key creation is a preventive control that blocks the action unless the user authenticates with a multi-factor authentication device; it does not generate any alert or notification when a key is created. The requirement would only stop unauthorized users without MFA, but an insider threat with valid MFA could still create a key without any real-time notification. Since the goal is to be alerted to the event, this option fails to deliver the necessary monitoring, not because it is ineffective as a security hardening measure.
- ✓
Create an Amazon EventBridge rule that matches the CreateAccessKey event and targets an SNS topic.
Why this is correct
EventBridge can ingest CloudTrail API calls as events, and a rule with an event pattern filtering for the 'CreateAccessKey' API call from the IAM service will trigger in real time. The rule's target can be an SNS topic, which then sends notifications (e.g., email, SMS) to subscribers, providing immediate alerting. This is the standard serverless pattern for reacting to AWS API activity because it is real-time, scalable, and requires no polling or log parsing.
- ✗
Write a Lambda function that periodically scans CloudTrail logs in S3 and sends alerts.
Why it's wrong here
Writing a Lambda function that periodically scans CloudTrail logs in S3 is an indirect and inefficient approach because CloudTrail typically delivers log files to S3 in 5-minute increments, so alerts would be delayed by that interval plus processing time. Additionally, the Lambda would need to list and read objects each time, parse JSON records, and maintain checkpointing to avoid duplicate alerts, adding significant operational complexity. EventBridge provides a built-in, event-driven integration that reacts instantly to the CloudTrail event without the need for custom scanning logic or a separate scheduling mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.