Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator needs to detect when an IAM user attempts to modify an Amazon S3 bucket policy in the production AWS account. The administrator wants to receive an email notification within 5 minutes of such an event. The solution must use AWS managed services with no custom code. Which combination of services should the administrator use?

⚠ Common exam trap

Many exam-takers confuse S3 event notifications (object-level) with CloudTrail (management-level), or they assume CloudWatch Logs metric filters are the only way to trigger alarms from logs, overlooking EventBridge's direct event-driven capability for real-time notification without custom code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail, Amazon CloudWatch Events (Amazon EventBridge), and Amazon SNS

AWS CloudTrail captures the S3 bucket policy modification as a management event, which can be sent to Amazon EventBridge (formerly CloudWatch Events) as a real-time event. EventBridge can then trigger an SNS topic to send an email notification within minutes, all using fully managed services with no custom code required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail, Amazon CloudWatch Events (Amazon EventBridge), and Amazon SNS

    Why this is correct

    CloudTrail captures the IAM user's API attempt as a management event, and an Amazon EventBridge rule can match the exact API call (for example, PutBucketPolicy) using event patterns. The rule then sends the event to an SNS topic, which delivers an email notification. This pipeline is fully managed, near-real-time, and requires no custom code.

  • ✗

    AWS CloudTrail, Amazon CloudWatch Logs metric filter, and Amazon SNS

    Why it's wrong here

    CloudTrail can deliver events to CloudWatch Logs, where a metric filter counts occurrences of the IAM action and a CloudWatch alarm triggers SNS when the metric exceeds a threshold. However, this approach adds operational complexity and latency: you must set up a metric filter, an alarm with a minimum evaluation period of one minute, and IAM roles for log delivery, making detection less immediate than an EventBridge rule.

  • ✗

    Amazon S3 event notifications and Amazon SNS

    Why it's wrong here

    S3 event notifications are designed for object-level events within a bucket (like PutObject or DeleteObject) and can publish directly to SNS. They do not capture management events such as IAM user attempts to change bucket policies; those actions are recorded as CloudTrail management events. Therefore, this option cannot detect the required IAM user activity.

  • ✗

    AWS CloudTrail, AWS Lambda, and Amazon SNS

    Why it's wrong here

    This architecture works technically because CloudTrail can invoke a Lambda function to parse events and publish a message to SNS, but it requires you to author and manage custom Lambda code. The administrator explicitly wants to avoid custom code, so this option introduces unnecessary maintenance, a potential point of failure, and deployment overhead compared to a serverless EventBridge rule.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.