Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company uses Amazon S3 to store sensitive data. The SysOps administrator needs to ensure that any attempt to upload an object with server-side encryption disabled is immediately detected and the administrator is notified. The administrator has enabled AWS CloudTrail and is logging S3 data events. Which approach should the administrator use to achieve this?

⚠ Common exam trap

A common mix-up: candidates confuse S3 event notifications (which trigger on all PutObject operations without filtering) with CloudWatch Events (which can filter on API call details), leading them to choose Option A despite its inability to detect missing encryption headers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a CloudWatch Events rule that matches PutObject API calls without the encryption header and triggers an SNS notification.

CloudWatch Events (now Amazon EventBridge) can filter API calls captured by CloudTrail for PutObject operations that lack the x-amz-server-side-encryption header, and then trigger an SNS notification in near real-time. This ensures immediate detection and notification of any upload with server-side encryption disabled, meeting the requirement for instant alerting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable S3 event notifications to send events to SNS for all PutObject operations.

    Why it's wrong here

    S3 event notifications are generated after an object is stored and include only basic metadata such as bucket, key, size, and ETag; they do not contain the original HTTP request headers. Because the encryption header (e.g., x-amz-server-side-encryption) is not part of the notification payload, you cannot use these notifications to detect whether a PutObject call omitted encryption. This makes them unsuitable for real-time, header-sensitive security alerts.

  • ✓

    Create a CloudWatch Events rule that matches PutObject API calls without the encryption header and triggers an SNS notification.

    Why this is correct

    A CloudWatch Events (now EventBridge) rule can monitor CloudTrail S3 data events to inspect the requestParameters of each PutObject API call. CloudTrail logs the x-amz-server-side-encryption header in the requestParameters block, so a rule pattern can match when that parameter is absent, identifying unencrypted uploads. The rule then triggers an SNS notification, providing immediate, per-request detection that is not possible with other options.

  • ✗

    Create an AWS Config rule to detect objects without encryption.

    Why it's wrong here

    AWS Config rules evaluate the configuration state of existing resources either periodically or when a configuration change is detected, not live API requests. While a Config rule can identify objects that lack server-side encryption, it runs on a schedule (or after state changes), introducing delay and lacking the ability to inspect the specific upload request's headers. Thus, it cannot provide the immediate, real-time API-level alerting required here.

  • ✗

    Use S3 Inventory to generate a daily report of unencrypted objects.

    Why it's wrong here

    S3 Inventory generates a daily or weekly report in CSV or Parquet format that lists object metadata, including encryption status. This batch report can show which objects are unencrypted, but it is not real-time and does not capture the original PutObject request headers. It cannot trigger an immediate notification about a specific API call, making it unsuitable for the required real-time alerting.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.