SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company uses AWS CloudTrail to log API calls in a multi-account environment. The security team wants to be alerted when an IAM user in the production account modifies a security group to allow inbound SSH from 0.0.0.0/0. Which combination of actions should be taken to meet this requirement?
⚠ Common exam trap
Test-takers frequently confuse AWS Config rules (which are reactive and evaluate configuration state) with CloudWatch metric filters (which provide real-time alerting on API calls), leading them to choose Option A despite its inability to trigger immediate notifications on the specific event.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stream CloudTrail logs to CloudWatch Logs, create a metric filter for the specific API call, and set a CloudWatch Alarm that sends a notification to an SNS topic.
CloudTrail logs can be streamed to CloudWatch Logs, where a metric filter can be created to match the specific API call (e.g., AuthorizeSecurityGroupIngress with a CIDR of 0.0.0.0/0 and port 22). A CloudWatch Alarm based on that metric can then trigger an SNS notification, providing a real-time alert for the exact security group modification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config managed rule 'restricted-ssh' to detect the security group change and trigger an SNS notification.
Why it's wrong here
The AWS Config managed rule 'restricted-ssh' checks whether security groups allow unrestricted SSH access from the internet (port 22 from 0.0.0.0/0). It evaluates the current configuration state of resources rather than the API call that changed them, so it cannot directly detect a specific CloudTrail event like AuthorizeSecurityGroupIngress. Even if configured with an SNS topic for non-compliance notifications, it only alerts when a security group is non-compliant at the time of evaluation, missing the event context and potentially generating stale or false positives.
- ✗
Enable AWS Security Hub and configure a custom insight to detect the security group modification.
Why it's wrong here
AWS Security Hub primarily aggregates and analyzes findings from other security services such as GuardDuty, Inspector, and Config. A custom insight lets you query and group those findings, but it does not ingest or analyze CloudTrail logs directly. To detect a security group modification via Security Hub, you would need to create a custom rule or use a Lambda function to process findings—none of which are accomplished by an insight. Thus, this approach is indirect and fails to provide the immediate, event-driven alerting that the question requires.
- ✗
Create an AWS Lambda function that is triggered by CloudTrail events and publishes to SNS.
Why it's wrong here
CloudTrail does not have a native trigger that invokes Lambda functions directly; it delivers logs to an S3 bucket or CloudWatch Logs. While you could create a Lambda function that is invoked by CloudWatch Logs via a subscription filter, or by Amazon EventBridge for matching API events, the option as stated is technically incorrect. Moreover, using Lambda for this purpose adds complexity and latency compared to the standard CloudWatch metric filter and alarm pattern, which directly counts matching events and publishes to SNS without additional coding or infrastructure.
- ✓
Stream CloudTrail logs to CloudWatch Logs, create a metric filter for the specific API call, and set a CloudWatch Alarm that sends a notification to an SNS topic.
Why this is correct
Streaming CloudTrail logs to CloudWatch Logs is the foundation for real-time monitoring of API activity. You can then create a CloudWatch Logs metric filter that matches the specific API call, such as AuthorizeSecurityGroupIngress or RevokeSecurityGroupIngress, and increments a custom metric. Finally, set a CloudWatch alarm on that metric with a threshold of one, which triggers an SNS notification to the designated topic. This is the standard, event-driven method that provides immediate alerting with minimal overhead and is the recommended pattern for API call monitoring.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.