SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company uses AWS CloudTrail to log API activity. The security team needs to be notified immediately when an IAM user creates a new access key. Which combination of steps should a SysOps administrator take? (Choose TWO.)
⚠ Common exam trap
Watch out — candidates often think CloudTrail can directly send notifications to SNS (Option C) or that AWS Config rules are suitable for real-time event-driven alerts (Option B), but neither is correct for immediate notification of a specific API call.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudWatch Logs metric filter for the 'CreateAccessKey' event.
CloudWatch Logs metric filters allow you to extract specific patterns from CloudTrail log data, such as the 'CreateAccessKey' event, and convert them into a metric. This enables you to monitor for this specific API call and trigger an alarm when it occurs, meeting the requirement for immediate notification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a CloudWatch Logs metric filter for the 'CreateAccessKey' event.
Why this is correct
A CloudTrail trail that is integrated with CloudWatch Logs streams each API event as a JSON log record. A metric filter using a pattern such as `{ $.eventName = "CreateAccessKey" }` scans every incoming log event and increments a CloudWatch metric whenever a new access key is created. This is the core detection step because it transforms raw CloudTrail API activity into a trackable, numerical signal that downstream alarms can act on.
- ✗
Enable AWS Config rules to detect changes to IAM users.
Why it's wrong here
AWS Config rules evaluate the recorded configuration state of AWS resources, such as the properties of an IAM user or whether access keys are rotated, and they run on a periodic or configuration-change trigger. They do not inspect the CloudTrail event history in real time, so they cannot match individual CreateAccessKey API calls and immediately start a notification workflow. This approach is therefore aimed at continuous compliance auditing, not real-time API activity monitoring.
- ✗
Configure CloudTrail to send notifications directly to Amazon SNS.
Why it's wrong here
CloudTrail does not have an SNS topic as a direct destination for API events; its standard delivery targets are Amazon S3 for log files and CloudWatch Logs for optional streamed events. To trigger an SNS notification from CloudTrail data, you must create a CloudWatch Logs metric filter with a CloudWatch alarm, or use an EventBridge rule, because CloudTrail itself will not publish to SNS when an event occurs. Relying on a direct CloudTrail-to-SNS hookup is technically impossible.
- ✓
Create a CloudWatch alarm based on the metric filter and publish to an SNS topic.
Why this is correct
A CloudWatch alarm sits on the metric produced by the CreateAccessKey metric filter and continuously evaluates whether the count is greater than zero over a one-minute period. When a match occurs, the alarm transitions to ALARM and invokes its configured SNS action to send the notification, which completes the two-step detection-and-alerting workflow. This option is correct, but it only provides the notification half of the solution and is meaningless without the metric filter feeding it data.
- ✗
Create an Amazon EventBridge rule to match the 'CreateAccessKey' API call.
Why it's wrong here
Amazon EventBridge can match a CreateAccessKey API call with an event pattern like eventSource `aws.iam` and eventName `CreateAccessKey`, and it can route that event directly to an SNS topic, so this is a valid alternative in a different architecture. However, this question's expected correct answer is built on the CloudTrail-to-CloudWatch-Logs metric filter and alarm pair, not on EventBridge. Choosing this rule does not advance the prescribed solution, which is why it is marked incorrect in this exam context.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS CloudTrail to log API activity. The security team wants to be alerted when an IAM user creates a new access key. Which THREE steps should the SysOps administrator take to meet this requirement?
hard- A.Configure the CloudTrail trail to deliver logs directly to an SNS topic.
- ✓ B.Configure the Lambda function to publish a custom metric to CloudWatch.
- ✓ C.Set a CloudWatch alarm on the custom metric to send an Amazon SNS notification when the metric exceeds a threshold.
- ✓ D.Create a CloudWatch Logs subscription filter that sends matching log events to an AWS Lambda function.
- E.Create an Amazon EventBridge rule that matches the CreateAccessKey event and triggers an SNS notification.
Why B: The Lambda function processes CloudWatch Logs subscription filter events and publishes a custom metric to CloudWatch. This custom metric can then trigger a CloudWatch alarm (Option C) to send an SNS notification, meeting the requirement. The combination of a CloudWatch Logs subscription filter (Option D) with a Lambda function is the standard pattern for real-time log-based alerting when CloudTrail logs are delivered to CloudWatch Logs.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.