Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company uses Amazon CloudWatch to monitor its AWS resources. The operations team needs to receive email notifications when the root user performs any action in the AWS account. Which combination of services should the SysOps administrator use to meet this requirement?

⚠ Common exam trap

Watch out — candidates often confuse AWS Config (resource configuration tracking) with CloudTrail (API activity logging), or assume CloudWatch Logs alone can filter events without a metric filter and CloudTrail integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail, Amazon CloudWatch Logs metric filter, and Amazon SNS.

AWS CloudTrail logs all API activity, including root user actions. By sending these logs to CloudWatch Logs, you can create a metric filter that matches root user events (e.g., `userIdentity.type = "Root"`). When the metric filter triggers a CloudWatch alarm, it publishes a notification to an SNS topic, which sends an email to subscribers. This combination ensures real-time notification of root user actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch Logs and Amazon Simple Notification Service (SNS).

    Why it's wrong here

    Without AWS CloudTrail, CloudWatch Logs has no source of root user API activity to analyze. While CloudWatch Logs can host a metric filter and trigger a CloudWatch alarm, it needs log events delivered by CloudTrail to detect root credential usage. SNS merely delivers the resulting alert; it cannot supply or generate the root-user event data. Therefore, this combination omits the critical auditing service that captures the actual root user API calls.

  • ✓

    AWS CloudTrail, Amazon CloudWatch Logs metric filter, and Amazon SNS.

    Why this is correct

    This solution uses CloudTrail as the authoritative audit source, delivering root user API activities to a CloudWatch Logs log group. A metric filter with a pattern for root user events (such as userIdentity.type equal to Root) generates a numeric metric from those log entries, and a CloudWatch alarm on that metric triggers an SNS notification when the threshold is breached. This pipeline provides real-time, event-driven alerts for the required root user monitoring.

  • ✗

    AWS Trusted Advisor and Amazon Simple Email Service (SES).

    Why it's wrong here

    Trusted Advisor inspects account security best practices but does not generate real-time event-driven notifications for root user API actions; CloudTrail and Amazon SNS are required to capture and deliver those alerts. This option is tempting because Trusted Advisor does flag root user access keys as a security concern, making it seem relevant for root user monitoring, but it only provides periodic checks, not immediate action-based notifications.

  • ✗

    AWS Config, Amazon CloudWatch Events, and Amazon SNS.

    Why it's wrong here

    AWS Config is designed to record and evaluate resource configuration changes, not to audit which principal performed an API action. It can detect that a security group was modified, but it cannot reliably identify that the change was made by the root user, and it lacks event-by-event API call detail. CloudWatch Events (EventBridge) can route events, but with Config as the source it would receive configuration change notifications, not the root user credential usage events needed. The missing CloudTrail component means root user API calls are never captured for this alerting pipeline.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.