AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company has a multi-Region trail that delivers AWS CloudTrail management events to an S3 bucket and to a CloudWatch Logs log group. A metric filter and alarm on the log group notify the security team when the iam:DeleteRole API is invoked, but the notification sometimes arrives more than 5 minutes after the call. The team must receive alerts as quickly as possible while continuing to use CloudTrail data and keeping operational overhead low. Which approach meets these requirements?
Create an EventBridge rule that matches iam:DeleteRole events from the default event bus and publishes the matches to an SNS topic.
Enable CloudTrail Lake, create an event data store filtered for iam:DeleteRole, and configure the data store to send matching events to an SNS topic.
Add a subscription filter on the existing CloudWatch Logs log group that streams the logs to a Lambda function which then publishes the event to SNS.
Replace the current trail with separate single-Region trails that deliver to CloudWatch Logs in each Region to reduce delivery latency before the metric filter fires.
CloudTrail management events are automatically sent to Amazon EventBridge in near real time. Creating a rule that matches DeleteRole API calls and targets an SNS topic produces an almost immediate notification and requires no additional log ingestion or periodic metric evaluation. Metric filters evaluate logs only after delivery to CloudWatch Logs, introducing minutes of delay. CloudTrail Lake currently supports event search and analytics, not real-time push. Subscription filters on the log group or creating separate regional trails still rely on CloudWatch Logs processing and do not guarantee sub-minute delivery.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Amazon EventBridge?
Open an interactive chat with Bash
How does Amazon SNS work in delivering notifications?
Open an interactive chat with Bash
Why is CloudTrail integrated with EventBridge?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Monitoring, Logging, Analysis, Remediation, and Performance Optimization
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .