Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company uses AWS CloudTrail to log API activity. The security team wants to be alerted when an IAM user creates a new access key. Which THREE steps should the SysOps administrator take to meet this requirement?

⚠ Common exam trap

The trap here is that candidates might think CloudTrail can directly send logs to SNS (Option A) or that a single EventBridge rule (Option E) is sufficient, but the exam expects the multi-step CloudWatch Logs subscription filter + Lambda + custom metric + alarm pipeline as the correct three-step solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Lambda function to publish a custom metric to CloudWatch.

The Lambda function processes CloudWatch Logs subscription filter events and publishes a custom metric to CloudWatch. This custom metric can then trigger a CloudWatch alarm (Option C) to send an SNS notification, meeting the requirement. The combination of a CloudWatch Logs subscription filter (Option D) with a Lambda function is the standard pattern for real-time log-based alerting when CloudTrail logs are delivered to CloudWatch Logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the CloudTrail trail to deliver logs directly to an SNS topic.

    Why it's wrong here

    CloudTrail trails can only deliver log files to an Amazon S3 bucket or to Amazon CloudWatch Logs; SNS is not a supported direct destination. If you attempted to configure SNS as a delivery target, CloudTrail would reject it because the service lacks an integration for pushing events straight to a topic. Even if delivery were possible, a raw SNS notification would not provide the filtering, aggregation, or numeric threshold evaluation needed to set a meaningful alarm. The correct architecture uses CloudWatch Logs as the delivery point, then a subscription filter and Lambda to process events.

  • ✓

    Configure the Lambda function to publish a custom metric to CloudWatch.

    Why this is correct

    The Lambda function that receives the CloudWatch Logs subscription filter must parse the base64 gzip-compressed log data, extract only the CreateAccessKey events, and call PutMetricData to publish a custom CloudWatch metric (e.g., IAMAccessKeyCreatedCount) in a custom namespace. Publishing a custom metric is essential because CloudTrail log entries are not natively represented as CloudWatch metrics, so you need this transformation to enable threshold-based alarm evaluation. The metric count can be incremented for each matching event, allowing the later CloudWatch alarm to compare against a threshold. Without this step, there is no numeric time-series data on which to set an alarm.

  • ✓

    Set a CloudWatch alarm on the custom metric to send an Amazon SNS notification when the metric exceeds a threshold.

    Why this is correct

    Once the Lambda publishes the custom metric to CloudWatch, you configure an alarm that monitors that metric, typically with a statistic such as Sum or SampleCount over a 1- or 5-minute period. When the metric value exceeds the threshold (for example, greater than 0, indicating at least one CreateAccessKey event), the alarm transitions to ALARM state and automatically publishes to an SNS topic. This SNS notification is what actually alerts the security team via email, SMS, or other subscribed endpoints. This step closes the alerting loop and directly meets the requirement to "notify the security team."

  • ✓

    Create a CloudWatch Logs subscription filter that sends matching log events to an AWS Lambda function.

    Why this is correct

    To route CloudTrail log events from CloudWatch Logs to AWS Lambda, you must establish a subscription filter using a pattern that matches the specific API activity. A filter pattern like { ($.eventName = "CreateAccessKey") } ensures only relevant log events are sent to the Lambda function in real time, avoiding processing of all CloudTrail entries. This is the required ingestion mechanism when your source is CloudWatch Logs; without it, Lambda would never see the events to publish metrics. The filter invokes the chosen Lambda function with the matched log events, enabling the metric generation for the subsequent alarm.

  • ✗

    Create an Amazon EventBridge rule that matches the CreateAccessKey event and triggers an SNS notification.

    Why it's wrong here

    An EventBridge rule that matches the CreateAccessKey event and directly triggers an SNS topic is a perfectly valid and often simpler alternative architecture—it does not require CloudWatch Logs, Lambda, or custom metrics. However, the question specifically asks for the three steps to implement when using CloudTrail logs delivered to CloudWatch Logs, which mandates a subscription filter and a Lambda function. If you chose this option, you would be implementing a separate event-driven pipeline rather than the CloudWatch Logs-based design described in the stem. Therefore, it is incorrect because it is not one of the three required steps in that particular architecture.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.