SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator needs to detect unauthorized changes to security groups and automatically notify the operations team. Which two AWS services should be part of the solution? (Choose 2.)
⚠ Common exam trap
Many candidates confuse Amazon S3 Transfer Acceleration with S3 event notifications or S3 server access logging, mistakenly thinking it can trigger alerts, when in fact it is solely a performance optimization for uploads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail.
AWS CloudTrail is correct because it records API calls made to create, modify, or delete security groups, providing the audit trail needed to detect unauthorized changes. By enabling CloudTrail on the account and configuring a trail to deliver logs to Amazon S3, the administrator can monitor security group events such as AuthorizeSecurityGroupIngress or RevokeSecurityGroupEgress. This log data is essential for identifying when a change occurred, who made it, and from which source IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail.
Why this is correct
AWS CloudTrail is the service that continuously records AWS API activity, capturing management events such as AuthorizeSecurityGroupIngress and RevokeSecurityGroupIngress. Each event includes the principal who made the request, the source IP address, the request parameters, and the timestamp, giving administrators a complete audit trail. This makes CloudTrail the foundational data source for detecting unauthorized security group modifications.
- ✓
Amazon EventBridge.
Why this is correct
Amazon EventBridge can be configured with an event pattern that matches specific CloudTrail events, such as security group ingress changes, and then route those events to targets like an SNS topic for alerting or a Lambda function for automated remediation. It acts as a reactive event bus rather than a durable audit store; without CloudTrail delivering events to it, EventBridge has no visibility into the change itself. Therefore, EventBridge is correct in the sense that it can help detect the change by alerting on CloudTrail records, but only as part of an event-driven detection pipeline.
- ✗
Amazon S3 Transfer Acceleration.
Why it's wrong here
Amazon S3 Transfer Acceleration uses AWS edge locations to speed up uploads to S3 buckets over the public internet by routing traffic over the AWS backbone network. It exists solely to improve data-transfer performance and has no mechanism for inspecting or logging AWS service API calls. A security group modification is a management-plane operation in EC2/VPC and is entirely outside S3 Transfer Acceleration's scope, so it cannot detect unauthorized changes.
- ✗
AWS Snowball Edge.
Why it's wrong here
AWS Snowball Edge is a ruggedized, physical appliance designed for offline data transfer and edge computing workloads. It has no integration with AWS control-plane APIs such as EC2 or VPC, and it neither records nor monitors changes to security group rules. Because it operates outside the AWS management plane, it cannot provide the audit trail needed to detect unauthorized AuthorizeSecurityGroupIngress calls.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A SysOps administrator needs to track changes to security group rules in a VPC. Which AWS services can be used to monitor and log these changes? (Choose TWO.)
easy- A.VPC Flow Logs.
- B.AWS Trusted Advisor.
- ✓ C.AWS CloudTrail.
- ✓ D.AWS Config.
- E.Amazon CloudWatch Logs.
Why C: AWS CloudTrail is correct because it records API calls made to the Amazon EC2 service, including AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress, and CreateSecurityGroup. These events capture the identity, source IP, and timestamp of every change to security group rules, providing an audit trail for compliance and troubleshooting.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.