Courseiva
Security and Compliance →hardMultiple Select

SOA-C02 Security and Compliance Practice Question

A company uses AWS CloudTrail to log API calls. The SysOps team needs to ensure that any attempt to disable CloudTrail logging is immediately detected and triggers an automated response. Which combination of services should be used? (Choose two.)

⚠ Common exam trap

It's easy for candidates to choose AWS Config because it is associated with compliance and monitoring, but they miss that Config is reactive and not designed for real-time event-driven automation, whereas EventBridge and Lambda provide the immediate detection and response required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Lambda

Amazon EventBridge (CloudWatch Events) can monitor CloudTrail API calls in real time and trigger an AWS Lambda function when a `StopLogging` or `UpdateTrail` API call is detected. Lambda then executes the automated response, such as re-enabling logging or sending an alert. This combination provides event-driven detection and remediation without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config does not monitor API calls or provide event-driven automation; it records resource configuration state and evaluates compliance on a schedule or when a configuration change is detected. It could eventually identify that CloudTrail was disabled, but it cannot react to the StopLogging API call in real time and would not directly restore logging.

  • ✓

    AWS Lambda

    Why this is correct

    AWS Lambda is the correct service because it can run custom remediation code in response to an EventBridge rule that detects a CloudTrail StopLogging API call. The Lambda function uses the AWS SDK to call StartLogging or UpdateTrail, automatically re-enabling the trail without manual intervention and requiring no servers to manage.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a security assessment service that scans compute resources for software vulnerabilities, network reachability, and unintended exposure; it does not process CloudTrail events or execute any remediation actions on AWS APIs. Therefore, it is entirely unsuitable for automatically re-enabling CloudTrail logging when a stop API call occurs.

  • ✗

    Amazon Simple Queue Service (SQS)

    Why it's wrong here

    Amazon SQS is a message queuing service that buffers and delivers messages between distributed components, but it has no compute capability to invoke AWS APIs or evaluate event content. While SQS could queue notifications from CloudTrail or EventBridge, it cannot by itself trigger the re-enabling of CloudTrail logging; a consumer like Lambda would be required.

  • ✓

    Amazon EventBridge (CloudWatch Events)

    Why this is correct

    Amazon EventBridge is correct because it can be configured with an event pattern that matches the CloudTrail event for an API action such as StopLogging, and then route that event to a Lambda function for immediate remediation. It provides the real-time event-detection layer that makes the CloudTrail log entry actionable, acting as the necessary trigger for the automation.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.