AnswerCorrect answer: B — an EventBridge rule on ConsoleLogin with a Root userIdentity triggers an SNS notification as soon as root signs in.
A company has a strict policy against using root credentials. The company’s security team wants to be alerted as soon as possible when root credentials are used to sign in to the AWS Management Console. How should the security team achieve this goal?
Use AWS Lambda to periodically query AWS CloudTrail for console login events and send alerts using Amazon Simple Notification Service (Amazon SNS).
Use Amazon EventBridge to monitor console logins and direct them to Amazon Simple Notification Service (Amazon SNS). Correct Answer
Use Amazon Athena to query AWS IAM Identity Center logs and send alerts using Amazon Simple Notification Service (Amazon SNS) for root login events.
Configure AWS Resource Access Manager to review the access logs and send alerts using Amazon Simple Notification Service (Amazon SNS).
Community Votes
B
100%
100% of anonymous learners picked answer B.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
EventBridge consumes CloudTrail management events and can match the root ConsoleLogin pattern, triggering SNS immediately (B)—the most direct, real-time approach. A Lambda polling CloudTrail is slower and custom. C (Athena on IAM Identity Center logs) is batch query, not real-time. D (RAM) reviews access, not login alerts. B is correct.
To be alerted as soon as root signs in to the console, create an Amazon EventBridge rule with an event pattern matching ConsoleLogin where userIdentity.type is Root, and set the target to an SNS topic. CloudTrail (enabled by default) delivers management events to EventBridge, so the alert fires in near real time without polling or custom code.
Polling CloudTrail with a Lambda (A)—adds latency and custom code versus the event-driven rule. Querying IAM Identity Center logs with Athena (C)—that is batch analysis, not a near-real-time alert. Using Resource Access Manager (D)—RAM shares resources, it does not monitor or alert on logins. EventBridge→SNS (B) is purpose-built.
Community Discussion (4 comments)
phmeeeee👍 1Selected: B
B - To trigger the EventBridge based-on root event
TareDHakim👍 1Selected: B
EventBridge, create a rule with the following event pattern: json Copy code { "detail": { "eventName": ["ConsoleLogin"], "userIdentity": { "type": ["Root"] }, "responseElements": { "ConsoleLogin": ["Success"] } } } This ensures that only root user login events trigger the rule
IPLogic👍 1Selected: B
The most effective way to achieve this goal is to use Amazon EventBridge. EventBridge Rule: Create an EventBridge rule that triggers on console login events. Target SNS Topic: Configure the rule to send notifications to an SNS topic. SNS Subscriptions: Subscribe relevant security team members or security tools to the SNS topic. This approach offers several advantages: Real-time Monitoring: EventBridge can detect and respond to events in real-time, ensuring immediate alerts for root logins. Scalability: EventBridge can handle a large volume of events efficiently, making it suitable for large-scale environments. Flexibility: EventBridge can be integrated with various AWS services, allowing for customization and automation of response actions. Cost-Effective: EventBridge is a serverless service, so you only pay for the resources consumed.
723993f👍 1Selected: B
it tests you if you know that cloudtrail is enabled by default, which can be consumed by eventbridge and sns for quick alerts
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
CloudTrail management events (including root ConsoleLogin) are delivered to EventBridge by default. An EventBridge rule with an event pattern filtering on eventName ConsoleLogin and userIdentity.type Root, targeting an SNS topic, produces a near-real-time alert the moment root signs in—no polling, no custom code.
Why the Other Options Are Wrong
A uses a Lambda that periodically queries CloudTrail, which is slower and requires custom code. C uses Athena on IAM Identity Center logs, which is batch querying, not a real-time alert. D uses RAM, which shares resources across accounts and does not alert on console logins. B is the correct event-driven approach.
Community Comment Notes
Community voted B (100). Commenters noted CloudTrail is enabled by default and its events feed EventBridge, and an EventBridge rule on the Root ConsoleLogin pattern targeting SNS gives the fastest alert. B confirmed.