SOA-C02 Monitoring, Logging, and Remediation Practice Question
An organization wants to ensure that all changes to an S3 bucket policy are logged and immediately trigger a notification to the security team. What is the most efficient way to achieve this?
⚠ Common exam trap
Watch out — candidates often confuse S3 event notifications (which only cover object-level events) with CloudWatch Events (which can capture management API calls via CloudTrail), leading them to incorrectly select option D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudWatch Events rule that matches PutBucketPolicy API call and triggers an SNS topic.
CloudWatch Events (now Amazon EventBridge) can capture the PutBucketPolicy API call via a service-specific event pattern and route it to an SNS topic for immediate notification. This approach is the most efficient as it directly monitors the API call in real-time without polling or additional configuration, ensuring the security team is alerted the moment the policy changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a CloudWatch Events rule that matches PutBucketPolicy API call and triggers an SNS topic.
Why this is correct
CloudWatch Events (now Amazon EventBridge) can match the PutBucketPolicy API call by using an event pattern that filters CloudTrail's AWS API Call events. When the bucket policy is modified, the rule triggers an SNS topic in near-real-time, enabling immediate notification. This approach requires CloudTrail to be enabled and configured to record management events, and it is the only option here that provides real-time, actionable alerts for policy changes.
- ✗
Create a CloudWatch Alarm that monitors the S3 bucket's policy.
Why it's wrong here
A CloudWatch Alarm evaluates a numeric metric against a threshold, such as bucket size, request count, or latency, but S3 does not expose a metric that represents the bucket's policy or its changes. Since PutBucketPolicy is a control-plane API call rather than a metric, there is no underlying data point for a CloudWatch Alarm to monitor. Consequently, an alarm cannot detect a policy modification.
- ✗
Use AWS Config with a managed rule to detect policy changes.
Why it's wrong here
AWS Config evaluates the configuration of AWS resources against managed or custom rules, but this evaluation is performed on a periodic schedule (e.g., every 24 hours) or when a configuration change is detected, not in real-time. Although a rule like 's3-bucket-policy-not-more-permissive' can flag noncompliant policies, it does not provide immediate notification the instant a PutBucketPolicy call occurs. It is a governance and compliance tool, not a real-time security alerting mechanism.
- ✗
Enable S3 event notifications on the bucket for 'PutBucketPolicy' events.
Why it's wrong here
S3 event notifications are designed for object-level events in a bucket, such as s3:ObjectCreated:* or s3:ObjectRemoved:* events, and only for data-plane operations. The PutBucketPolicy API call is a control-plane operation that modifies the bucket's configuration, and it is not one of the supported event types in S3 event notifications. Therefore, you cannot configure S3 event notifications to react to bucket policy changes.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.