How to Get Immediate Notification When an S3 Object is Deleted
A company stores critical data in an S3 bucket and wants to be notified immediately when any object is deleted from the bucket. Which combination of services should the SysOps administrator use?
⚠ Common exam trap
The trap here is that candidates often overcomplicate the solution by choosing CloudTrail or Lambda, not realizing that S3 event notifications can directly trigger SNS for immediate alerts without additional services or delays.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an S3 event notification for 's3:ObjectRemoved:*' events to send to an SNS topic.
S3 event notifications can be configured to trigger on 's3:ObjectRemoved:*' events, which cover both permanent and versioned object deletions. These notifications can be sent directly to an SNS topic, enabling immediate notification without additional compute or logging overhead. This is the simplest and most direct approach for real-time alerts on object deletions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure an S3 event notification for 's3:ObjectRemoved:*' events to send to an SNS topic.
Why this is correct
S3 event notifications are the direct, native mechanism for reacting to object lifecycle events. Configuring a notification for the `s3:ObjectRemoved:*` prefix covers both individual `DeleteObject` and multi-object `DeleteObjects` API calls, and SNS can deliver an email immediately upon event publication. With an SNS topic subscribed to by email, the notification is pushed in near real-time, typically within seconds, with no polling or compute layer required. This makes it the simplest and most appropriate option for instant alerting.
- ✗
Enable S3 server access logging and send logs to CloudWatch Logs, then create a metric filter and alarm.
Why it's wrong here
S3 server access logging is an audit-oriented feature that writes log records as objects to a destination bucket, not a real-time notification stream. Log delivery is best-effort and can lag by hours, so you would need an external process (e.g., a custom script or Lambda) to periodically fetch and forward logs to CloudWatch Logs, then a metric filter and alarm to trigger on `DeleteObject` entries. This introduces significant latency and operational overhead, meaning it cannot satisfy a requirement for immediate notification when an object is removed.
- ✗
Use S3 event notifications to invoke a Lambda function that checks the object and sends an email.
Why it's wrong here
While S3 event notifications can invoke Lambda, using a Lambda function just to 'check' the object and send an email adds unnecessary complexity, latency, and cost. The S3 event payload already contains the bucket name, object key, and event type, so the function has no reason to inspect the object—and in fact the object is already deleted, so any attempt to read it would fail. Furthermore, SNS can send an email directly from the event notification, making Lambda an extraneous middle layer that introduces additional failure points and should be avoided for simple deletion alerts.
- ✗
Use AWS CloudTrail to log DeleteObject calls and create a CloudWatch Events rule to send an SNS notification.
Why it's wrong here
CloudTrail delivers logs asynchronously, typically with a delay of several minutes, meaning this option fails to provide immediate notification of object deletions. While CloudTrail correctly captures `DeleteObject` events, its logging mechanism is designed for auditing, security analysis, and compliance, where near real-time processing is not a strict requirement. It would be appropriate for scenarios needing post-event analysis or delayed alerts.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.