🔥 40% Off Crucial Exams Memberships — This Week Only

3 days, 8 hours remaining!

AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company has a multi-Region trail that delivers AWS CloudTrail management events to an S3 bucket and to a CloudWatch Logs log group. A metric filter and alarm on the log group notify the security team when the iam:DeleteRole API is invoked, but the notification sometimes arrives more than 5 minutes after the call. The team must receive alerts as quickly as possible while continuing to use CloudTrail data and keeping operational overhead low. Which approach meets these requirements?

  • Add a subscription filter on the existing CloudWatch Logs log group that streams the logs to a Lambda function which then publishes the event to SNS.

  • Enable CloudTrail Lake, create an event data store filtered for iam:DeleteRole, and configure the data store to send matching events to an SNS topic.

  • Create an EventBridge rule that matches iam:DeleteRole events from the default event bus and publishes the matches to an SNS topic.

  • Replace the current trail with separate single-Region trails that deliver to CloudWatch Logs in each Region to reduce delivery latency before the metric filter fires.

AWS Certified CloudOps Engineer Associate SOA-C03
Monitoring, Logging, Analysis, Remediation, and Performance Optimization
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot