Use an organizational CloudTrail trail with CloudWatch Logs metric filters and alarms to SNS

Answer Correct answer: A — an organizational CloudTrail trail with CloudWatch Logs metric filters and CloudWatch alarms forwards alerts to SNS in near real time.

A company recently adopted new compliance standards that require all user actions in AWS to be logged. The user actions must be logged for all accounts that belong to an organization in AWS Organizations. The company needs to set alarms that respond when specified actions occur. The alarms must forward alerts to an email distribution list. The alerts must occur in as close to real time as possible. Which solution will meet these requirements?

  1. Implement an AWS CloudTrail trail as an organizational trail. Configure the trail with Amazon CloudWatch Logs forwarding. In CloudWatch Logs, set a metric filter for any user action events that the company specifies. Create an Amazon CloudWatch alarm to provide alerts for occurrences within a reported period and to publish messages to an Amazon Simple Notification Service (Amazon SNS) topic. Correct Answer
  2. Implement an AWS CloudTrail trail. Configure the trail with Amazon CloudWatch Logs forwarding. In CloudWatch Logs, set a metric filter for any user action events that the company specifies. Create an Amazon CloudWatch alarm to provide alerts for occurrences within a reported period and to send messages to an Amazon Simple Queue Service (Amazon SQS) queue.
  3. Implement an AWS CloudTrail trail as an organizational trail. Configure the trail to store logs in an Amazon S3 bucket. Configure an Amazon EC2 instance to mount the S3 bucket as a file system to ingest new log files that are pushed to the S3 bucket. Configure the EC2 instance also to publish a message to an Amazon Simple Notification Service (Amazon SNS) topic when one of the specified actions is found in the logs.
  4. Implement an AWS CloudTrail trail. Configure the trail to store logs in an Amazon S3 bucket. Each hour, create an AWS Glue Data Catalog that references the S3 bucket. Configure Amazon Athena to initiate queries against the Data Catalog to identify the specified actions in the logs.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

An organizational trail covers every account in the org from one config, and CloudWatch Logs metric filters + CloudWatch alarms give near-real-time alerting to SNS email. SQS (B) and the EC2/S3/Glue/Athena batch paths (C/D) are slower and not real-time. Only A combines org trail + CloudWatch Logs + SNS.

All accounts in the organization must log every user action, and alerts must fire in near real time to an email list. An organizational CloudTrail trail writes to CloudWatch Logs; a metric filter on the specified user-action events drives a CloudWatch alarm that publishes to an SNS topic (email subscription), satisfying org-wide logging and real-time alerting.

Choosing B's SQS destination—SQS queues messages but does not alert an email list in real time without extra polling. Choosing C/D's S3+EC2/Glue/Athena paths—those are batch/periodic, violating the 'as close to real time as possible' requirement.

Community Discussion (4 comments)

Certified101 👍 6 Selected: A
A is correct https://aws.amazon.com/blogs/mt/monitor-changes-and-auto-enable-logging-in-aws-cloudtrail/
navid1365 👍 1 Selected: A
The answer is A
Nash101 👍 1
A is correct
Zek 👍 1
A is correct https://aws.amazon.com/blogs/mt/monitor-changes-and-auto-enable-logging-in-aws-cloudtrail/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An organizational CloudTrail trail centrally logs all user actions across every account in AWS Organizations. Forwarding to CloudWatch Logs lets a metric filter match the specified events and a CloudWatch alarm publish to an SNS topic, which emails the distribution list in near real time—meeting both the org-wide logging and real-time alerting requirements.

Why the Other Options Are Wrong

B sends alerts to SQS, which queues but does not notify an email list in real time without additional polling logic. C mounts S3 on an EC2 instance to scan logs, and D runs hourly Glue/Athena queries—both are periodic, not near-real-time, and add unnecessary infrastructure. A is the real-time, managed path.

Community Comment Notes

Community voted A (100). Commenters confirmed A with the CloudTrail auto-enable/CloudWatch integration blog. B, C, and D were dismissed as non-real-time or overly complex.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide