Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A SysOps administrator needs to detect unauthorized changes to security groups and automatically notify the operations team. Which two AWS services should be part of the solution? (Choose 2.)

⚠ Common exam trap

Many candidates confuse Amazon S3 Transfer Acceleration with S3 event notifications or S3 server access logging, mistakenly thinking it can trigger alerts, when in fact it is solely a performance optimization for uploads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail.

AWS CloudTrail is correct because it records API calls made to create, modify, or delete security groups, providing the audit trail needed to detect unauthorized changes. By enabling CloudTrail on the account and configuring a trail to deliver logs to Amazon S3, the administrator can monitor security group events such as AuthorizeSecurityGroupIngress or RevokeSecurityGroupEgress. This log data is essential for identifying when a change occurred, who made it, and from which source IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail.

    Why this is correct

    AWS CloudTrail is the service that continuously records AWS API activity, capturing management events such as AuthorizeSecurityGroupIngress and RevokeSecurityGroupIngress. Each event includes the principal who made the request, the source IP address, the request parameters, and the timestamp, giving administrators a complete audit trail. This makes CloudTrail the foundational data source for detecting unauthorized security group modifications.

  • ✓

    Amazon EventBridge.

    Why this is correct

    Amazon EventBridge can be configured with an event pattern that matches specific CloudTrail events, such as security group ingress changes, and then route those events to targets like an SNS topic for alerting or a Lambda function for automated remediation. It acts as a reactive event bus rather than a durable audit store; without CloudTrail delivering events to it, EventBridge has no visibility into the change itself. Therefore, EventBridge is correct in the sense that it can help detect the change by alerting on CloudTrail records, but only as part of an event-driven detection pipeline.

  • ✗

    Amazon S3 Transfer Acceleration.

    Why it's wrong here

    Amazon S3 Transfer Acceleration uses AWS edge locations to speed up uploads to S3 buckets over the public internet by routing traffic over the AWS backbone network. It exists solely to improve data-transfer performance and has no mechanism for inspecting or logging AWS service API calls. A security group modification is a management-plane operation in EC2/VPC and is entirely outside S3 Transfer Acceleration's scope, so it cannot detect unauthorized changes.

  • ✗

    AWS Snowball Edge.

    Why it's wrong here

    AWS Snowball Edge is a ruggedized, physical appliance designed for offline data transfer and edge computing workloads. It has no integration with AWS control-plane APIs such as EC2 or VPC, and it neither records nor monitors changes to security group rules. Because it operates outside the AWS management plane, it cannot provide the audit trail needed to detect unauthorized AuthorizeSecurityGroupIngress calls.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SysOps administrator needs to track changes to security group rules in a VPC. Which AWS services can be used to monitor and log these changes? (Choose TWO.)

easy
  • A.VPC Flow Logs.
  • B.AWS Trusted Advisor.
  • ✓ C.AWS CloudTrail.
  • ✓ D.AWS Config.
  • E.Amazon CloudWatch Logs.

Why C: AWS CloudTrail is correct because it records API calls made to the Amazon EC2 service, including AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress, and CreateSecurityGroup. These events capture the identity, source IP, and timestamp of every change to security group rules, providing an audit trail for compliance and troubleshooting.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.