Question 1 · choose 2
A production account runs all of its workloads in eu-west-1 and has a multi-Region CloudTrail trail that logs management events. The security team wants a message on an Amazon SNS topic within a minute or two whenever anyone creates an IAM access key in the account, without polling or scheduled queries. Which actions should the DevOps engineer take? (Choose TWO.)
- ACreate the rule on the default event bus in us-east-1, where events from IAM are recorded
- BCreate the rule on a custom event bus in eu-west-1 and have CloudTrail send its events to that bus directly
- CCreate the rule on the default event bus in eu-west-1, where all of the company's workloads and users operate
- DQuery the trail's events in CloudTrail Lake every two minutes and publish new CreateAccessKey calls to the topic
- EUse an event pattern with source aws.iam, detail-type AWS API Call via CloudTrail and eventName CreateAccessKey, with the SNS topic as target
Show the answer and why
ACreate the rule on the default event bus in us-east-1, where events from IAM are recorded
Correct
CloudTrail records events from global services such as IAM in us-east-1, and CloudTrail delivers its events to the default event bus only.
BCreate the rule on a custom event bus in eu-west-1 and have CloudTrail send its events to that bus directly
Incorrect
CloudTrail events are delivered only to the default event bus. A custom bus would need a forwarding rule from the default bus first.
CCreate the rule on the default event bus in eu-west-1, where all of the company's workloads and users operate
Incorrect
IAM events are recorded in us-east-1 regardless of where the caller works, so a rule in eu-west-1 never sees them.
DQuery the trail's events in CloudTrail Lake every two minutes and publish new CreateAccessKey calls to the topic
Incorrect
This is the polling the team wants to avoid, and CloudTrail Lake is no longer open to new customers.
EUse an event pattern with source aws.iam, detail-type AWS API Call via CloudTrail and eventName CreateAccessKey, with the SNS topic as target
Correct
API calls recorded by an active trail reach EventBridge with the detail type AWS API Call via CloudTrail, and a pattern on the event name selects CreateAccessKey.
EventBridge receives CloudTrail events only when a trail is logging, only on the default bus, and in the Region where CloudTrail records the event. For IAM, a global service, that Region is us-east-1.
AWS documentation