Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company uses AWS CloudTrail to log API activity. The SysOps administrator needs to receive an email notification whenever a new IAM user is created. Which AWS services should be used together to meet this requirement with the least operational overhead?

⚠ Common exam trap

The trap here is that candidates often overcomplicate the solution by adding Lambda or CloudWatch Logs, not realizing that EventBridge provides a direct, serverless integration between CloudTrail and SNS for real-time event-driven notifications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudTrail, Amazon EventBridge, and Amazon SNS

Amazon EventBridge can directly capture CloudTrail API events (such as CreateUser) and route them to an SNS topic for email notification without needing any custom code or additional infrastructure. This pattern minimizes operational overhead by using a fully managed event bus with built-in filtering and target routing, eliminating the need for Lambda functions or metric filter configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CloudTrail, Amazon SNS, and AWS Lambda

    Why it's wrong here

    While this combination can technically notify on IAM user creation, it requires a custom Lambda function to parse the CloudTrail event, filter for the `iam:CreateUser` API call, and then publish a message to SNS. This introduces code maintenance, deployment overhead, and potential delays or failure points compared to a fully managed integration. EventBridge provides built-in pattern matching for CloudTrail events, making it the simpler and more reliable choice.

  • ✗

    CloudTrail, Amazon CloudWatch Logs, and a metric filter with an alarm

    Why it's wrong here

    CloudTrail, CloudWatch Logs, and a metric filter correctly identify the logging and event detection mechanisms for IAM user creation. However, a CloudWatch Alarm, while excellent for monitoring metric filter matches, cannot directly send email notifications. It requires an Amazon SNS topic as an action to deliver emails, which is omitted here, thus failing to meet the 'email notification' requirement. This setup is otherwise fundamental for real-time operational monitoring and triggering automated responses based on specific log events.

  • ✓

    CloudTrail, Amazon EventBridge, and Amazon SNS

    Why this is correct

    Amazon EventBridge natively consumes CloudTrail management events, allowing you to create a rule that matches the `CreateUser` event and directly targets an SNS topic. Because EventBridge performs the filtering and delivers to SNS without any custom code, this is the simplest and most efficient serverless solution. The SNS topic then sends an email notification to the subscribed administrator immediately when the API call occurs.

  • ✗

    AWS Config and Amazon SNS

    Why it's wrong here

    AWS Config is a configuration tracking service that evaluates changes to resource settings, not a real-time API activity logger. While it can detect that an IAM user resource was created via configuration changes, it does so on its own compliance timeline and is not intended for per-API-call notification. The scenario specifically requires notification on an 'api activity' event, which CloudTrail provides but AWS Config does not.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS CloudTrail to record all API activity. The SysOps administrator needs to be alerted in real time when an IAM user creates a new access key. Which combination of AWS services should be used to create this alert?

medium
  • A.CloudTrail + Amazon S3 + Amazon SNS
  • B.CloudTrail + Amazon CloudWatch Logs + Amazon SNS
  • C.CloudTrail + AWS Config + Amazon SNS
  • ✓ D.CloudTrail + Amazon EventBridge + Amazon SNS

Why D: Amazon EventBridge can directly consume CloudTrail events in real time and trigger an SNS notification when an IAM user creates a new access key. EventBridge provides a serverless event bus that matches specific API calls (e.g., CreateAccessKey) using event patterns, enabling immediate alerting without additional polling or log processing.

Variation 2. A company is using AWS CloudTrail to log API activity. The security team wants to be notified when an IAM user attempts to modify an S3 bucket policy. Which actions should be taken to meet this requirement? (Select THREE.)

hard
  • A.Create a CloudWatch alarm on the number of PutBucketPolicy calls.
  • B.Enable CloudTrail data events for S3 to capture bucket policy changes.
  • ✓ C.Create an Amazon EventBridge rule that matches the PutBucketPolicy API call via CloudTrail.
  • ✓ D.Configure the EventBridge rule to send events to an SNS topic.
  • ✓ E.Ensure CloudTrail is logging management events for the S3 service.

Why C: Amazon EventBridge can match specific API calls (like PutBucketPolicy) by using CloudTrail as an event source. This allows the security team to trigger a notification when an IAM user attempts to modify an S3 bucket policy, without needing to poll or set up custom monitoring.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.