SOA-C02 Security and Compliance Practice Question
A SysOps administrator needs to detect when an IAM user attempts to modify an Amazon S3 bucket policy in the production AWS account. The administrator wants to receive an email notification within 5 minutes of such an event. The solution must use AWS managed services with no custom code. Which combination of services should the administrator use?
⚠ Common exam trap
Many exam-takers confuse S3 event notifications (object-level) with CloudTrail (management-level), or they assume CloudWatch Logs metric filters are the only way to trigger alarms from logs, overlooking EventBridge's direct event-driven capability for real-time notification without custom code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail, Amazon CloudWatch Events (Amazon EventBridge), and Amazon SNS
AWS CloudTrail captures the S3 bucket policy modification as a management event, which can be sent to Amazon EventBridge (formerly CloudWatch Events) as a real-time event. EventBridge can then trigger an SNS topic to send an email notification within minutes, all using fully managed services with no custom code required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail, Amazon CloudWatch Events (Amazon EventBridge), and Amazon SNS
Why this is correct
CloudTrail captures the IAM user's API attempt as a management event, and an Amazon EventBridge rule can match the exact API call (for example, PutBucketPolicy) using event patterns. The rule then sends the event to an SNS topic, which delivers an email notification. This pipeline is fully managed, near-real-time, and requires no custom code.
- ✗
AWS CloudTrail, Amazon CloudWatch Logs metric filter, and Amazon SNS
Why it's wrong here
CloudTrail can deliver events to CloudWatch Logs, where a metric filter counts occurrences of the IAM action and a CloudWatch alarm triggers SNS when the metric exceeds a threshold. However, this approach adds operational complexity and latency: you must set up a metric filter, an alarm with a minimum evaluation period of one minute, and IAM roles for log delivery, making detection less immediate than an EventBridge rule.
- ✗
Amazon S3 event notifications and Amazon SNS
Why it's wrong here
S3 event notifications are designed for object-level events within a bucket (like PutObject or DeleteObject) and can publish directly to SNS. They do not capture management events such as IAM user attempts to change bucket policies; those actions are recorded as CloudTrail management events. Therefore, this option cannot detect the required IAM user activity.
- ✗
AWS CloudTrail, AWS Lambda, and Amazon SNS
Why it's wrong here
This architecture works technically because CloudTrail can invoke a Lambda function to parse events and publish a message to SNS, but it requires you to author and manage custom Lambda code. The administrator explicitly wants to avoid custom code, so this option introduces unnecessary maintenance, a potential point of failure, and deployment overhead compared to a serverless EventBridge rule.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.