SOA-C02 Monitoring, Logging, and Remediation Practice Question
An organization has a production AWS environment with multiple VPCs and hundreds of EC2 instances. The security team wants to be alerted when any security group is modified. Which approach should a SysOps administrator use to meet this requirement with minimal overhead?
⚠ Common exam trap
Many exam-takers confuse CloudTrail event monitoring with AWS Config's configuration change detection, leading candidates to choose CloudTrail-based alarms despite the higher overhead and lack of direct compliance evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Config rules to detect security group changes and trigger an SNS notification.
AWS Config rules can continuously evaluate security group configurations against desired settings and trigger an SNS notification when a change is detected. This approach provides automated, event-driven monitoring with minimal operational overhead, as it does not require custom scripts or manual log analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable CloudTrail and create a CloudWatch alarm for each security group modification event.
Why it's wrong here
CloudTrail does log management events such as AuthorizeSecurityGroupIngress or RevokeSecurityGroupEgress, and you could create a CloudWatch Logs metric filter with a corresponding alarm to notify on each occurrence. However, this requires manually building and maintaining a filter pattern for every API action and does not continuously evaluate the resulting security group configuration against your desired policies. At scale, this becomes unwieldy, and it only alerts on discrete API calls rather than providing a compliance view of the current state.
- ✓
Use AWS Config rules to detect security group changes and trigger an SNS notification.
Why this is correct
AWS Config records every change to security group resources as a configuration item and can evaluate those changes using managed or custom rules. When a rule marks a security group as noncompliant, AWS Config can send an alert through an SNS topic that you configure, giving you immediate notification of the modification. This approach both detects the change and enforces your security policies, unlike simply logging API activity or monitoring traffic.
- ✗
Enable VPC Flow Logs and analyze them with Amazon Athena for security group changes.
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic reaching your VPC, including source and destination addresses, ports, protocols, and whether the traffic was accepted or rejected. They do not record or log changes to security group rules, so querying them with Athena would only show traffic patterns and not whether a security group was modified. Consequently, Flow Logs cannot fulfill the requirement to alert on security group changes.
- ✗
Deploy Amazon GuardDuty to monitor for security group modifications.
Why it's wrong here
Amazon GuardDuty is a threat detection service that analyzes network traffic, DNS query logs, and CloudTrail management events to identify malicious activity such as cryptocurrency mining, port scanning, or compromised instances. It does not monitor resource configuration changes like security group rule edits, and it is not designed to evaluate compliance with your desired security group policies. Relying on GuardDuty for this purpose would miss the exact change notifications you need.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.