Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company wants to ensure that it receives notifications whenever any AWS Identity and Access Management (IAM) user in the account creates a new access key. Which AWS service should be used to achieve this?

⚠ Common exam trap

Many exam-takers choose AWS CloudTrail because it logs API calls, but they overlook that CloudTrail alone cannot send notifications—it requires an event-driven service like CloudWatch Events/EventBridge to trigger alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Events

Amazon CloudWatch Events (now part of Amazon EventBridge) can capture API calls from AWS CloudTrail and trigger a notification (e.g., via SNS) when an IAM user creates a new access key. By setting up a rule that matches the `CreateAccessKey` API call, the company can receive real-time alerts for this specific action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and evaluates them against managed or custom rules, but it does not capture or act on real-time API calls. While it can deliver configuration snapshots and compliance notifications via SNS, that is for configuration drift, not for instant alerting on every AWS API action as described in the scenario.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is a governance, compliance, and audit service that captures a complete history of API activity, but it is purely a logging service and has no native alerting or notification mechanism. To notify you about a specific API call, you must feed CloudTrail events into a separate service like Amazon EventBridge (CloudWatch Events), which then triggers an SNS topic; CloudTrail itself cannot directly send notifications.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is a service that inspects your environment and offers recommendations across cost optimization, security, fault tolerance, and service limits. It performs periodic or on-demand checks, not real-time event monitoring, and it cannot be configured to listen for a specific API call and immediately send an SNS notification; it is fundamentally a static best-practice analyzer, not an event router.

  • ✓

    Amazon CloudWatch Events

    Why this is correct

    Amazon CloudWatch Events (now part of Amazon EventBridge) is the correct service because it can create rules that match real-time AWS API calls, such as those recorded by CloudTrail, and route them to targets like SNS topics for notification. For example, a rule can filter for a specific event source and event name, then invoke an SNS topic to alert administrators, providing the event-driven notification capability the company needs.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.