A security analyst is troubleshooting alerts for suspicious security group changes. The team stated that an Amazon CloudWatch alarm monitors the corresponding AWS CloudTrail events. The analyst tested by modifying a security group but received no alert. Which troubleshooting step should the analyst take?
Choose an answer
Tap an option to check your answer.
Correct answer: Verify that a CloudWatch Logs metric filter exists for the relevant CloudTrail events, that the filter is associated with an alarm, and that the alarm has a configured notification action..
Why this is the answer
The correct answer addresses the entire chain of events required for CloudTrail-based alerting. For a security group change to trigger an alert, CloudTrail must capture the event, a CloudWatch Logs metric filter must extract that specific event from the CloudTrail logs, the filter must be associated with a CloudWatch alarm, and that alarm must have a notification action (e.g., SNS topic) configured to send the alert. The analyst's test failing suggests a break in this chain. Incorrect options: CloudTrail being enabled is a prerequisite, but the problem implies it's already capturing events. S3 server access logging is unrelated to security group change alerts. CloudWatch dashboards visualize metrics but don't define the alerting logic itself. The analyst's IAM permissions are for viewing metrics, not for the alarm to function and send notifications.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed