AnswerCorrect answer: C — route Secrets Manager events to CloudWatch Logs, add a metric filter with anomaly detection on IncomingBytes, and alarm to SNS.
A company stores sensitive data in AWS Secrets Manager. A security engineer needs to design a solution to generate a notification email when anomalous GetSecretValue API calls occur. The security engineer has configured an Amazon EventBridge rule for all Secrets Manager events that AWS CloudTrail delivers. Which solution will meet these requirements?
Configure CloudTrail as the target of the EventBridge rule. Set up an attribute filter on the IncomingBytes attribute and enable anomaly detection. Create an Amazon Simple Notification Service (Amazon SNS) topic. Configure a CloudTrail alarm that uses the SNS topic to send the notification.
Configure CloudTrail as the target of the EventBridge rule. Set up an attribute filter on the IncomingBytes attribute and enable anomaly detection. Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure a CloudTrail alarm that uses the SQS queue to send the notification.
Configure Amazon CloudWatch Logs as the target of the EventBridge rule. Set up a metric filter on the IncomingBytes metric and enable anomaly detection. Create an Amazon Simple Notification Service (Amazon SNS) topic. Configure a CloudWatch alarm that uses the SNS topic to send the notification. Correct Answer
Configure Amazon CloudWatch Logs as the target of the EventBridge rule. Use CloudWatch Logs Insights query syntax to search for anomalous GetSecretValue API calls. Create an Amazon Simple Queue Service (Amazon SQS) queue. Configure a CloudWatch alarm that uses the SQS queue to send the notification.
Community Votes
C
100%
100% of anonymous learners picked answer C.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The path is EventBridge → CloudWatch Logs → metric filter (IncomingBytes) with anomaly detection → CloudWatch alarm → SNS (C). CloudTrail is the event source, not the rule target (A/B are wrong—CloudTrail is not an EventBridge target). D uses Logs Insights queries rather than the metric-filter+anomaly-detection+alarm pipeline the question describes. C is correct.
An EventBridge rule already catches Secrets Manager events from CloudTrail. To alert on anomalous GetSecretValue volume, set CloudWatch Logs as the rule target, add a metric filter on the IncomingBytes field with CloudWatch anomaly detection enabled, and create a CloudWatch alarm on that metric that notifies an SNS topic. The anomaly detection surfaces unusual call volume without manual thresholds.
Setting CloudTrail as the EventBridge target (A/B)—CloudTrail is the source of the events delivered to EventBridge, not a target of the rule. Using Logs Insights queries (D)—that is ad-hoc search, not the metric-filter plus anomaly-detection alarm the requirement describes. The CloudWatch Logs metric filter with anomaly detection (C) is the documented feature.
Community Discussion (3 comments)
TareDHakim👍 1Selected: C
amazing feature, which I had no idea existed.
IPLogic👍 1Selected: C
C. Configure Amazon CloudWatch Logs as the target of the EventBridge rule. Set up a metric filter on the IncomingBytes metric and enable anomaly detection. Create an Amazon Simple Notification Service (Amazon SNS) topic. Configure a CloudWatch alarm that uses the SNS topic to send the notification. EventBridge Rule and CloudWatch Logs: By configuring CloudWatch Logs as the target of the EventBridge rule, you can capture and store all relevant logs for further analysis. Metric Filter and Anomaly Detection: Setting up a metric filter on the IncomingBytes metric enables detailed monitoring and anomaly detection for specific API call patterns, such as the GetSecretValue API. SNS Topic for Notifications: Creating an SNS topic ensures that alerts are sent out immediately when an anomaly is detected. CloudWatch alarms can be configured to trigger notifications via SNS, providing timely alerts to the security team.
723993f👍 1Selected: C
C - using built-in anomaly detection in cloudwatch based on the volume of "what is being logged itself" https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CloudWatch-Logs-Monitoring-CloudWatch-Metrics.html#cwl-metrics https://medium.com/cyberark-engineering/unlocking-the-power-of-amazon-cloudwatch-anomaly-detection-for-secrets-manager-27a7ffd66498
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
With the EventBridge rule already capturing Secrets Manager CloudTrail events, the notification pipeline is: target CloudWatch Logs, create a metric filter on the IncomingBytes metric, enable CloudWatch anomaly detection on that filter, and attach a CloudWatch alarm that publishes to an SNS topic. Anomaly detection automatically flags unusual GetSecretValue volume and the alarm emails the notification—exactly the requirement.
Why the Other Options Are Wrong
A and B set CloudTrail as the EventBridge rule target, but CloudTrail is the event source, not a target; the rule should target CloudWatch Logs. D uses Logs Insights query syntax instead of the metric-filter plus anomaly-detection alarm pipeline the question specifies. C is the correct, built-in approach.
Community Comment Notes
Community voted C (100). Commenters described using CloudWatch's built-in anomaly detection on the logged volume (IncomingBytes) via a metric filter and SNS alarm, noting this feature was little-known but purpose-built. C confirmed.