Courseiva
Security and Compliance →easyMultiple Choice

CLF-C02 Security and Compliance Practice Question

A security auditor needs to know which IAM user deleted a specific S3 bucket last week, from which IP address the action was taken, and at what exact time. Which AWS service captures this information?

⚠ Common exam trap

A common mix-up: candidates confuse AWS Config's ability to track resource changes (like bucket deletion) with CloudTrail's ability to log the identity and source of the API call, leading them to select Config instead of CloudTrail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including S3 bucket deletion actions (DeleteBucket). It captures the identity of the IAM user, the source IP address, and the exact timestamp of each API call, which directly meets the auditor's requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch

    Why it's wrong here

    Amazon CloudWatch is an operational monitoring service for collecting metrics, logs, and alarms from AWS resources and applications. It does not natively record AWS API calls; although CloudTrail can be configured to deliver management event logs to CloudWatch Logs, the event data itself originates from CloudTrail, not CloudWatch. Thus, searching CloudWatch would only reveal the logs if you had already set up that CloudTrail-to-CloudWatch integration, and the definitive caller identity and timestamp for the S3 bucket deletion still come from CloudTrail, not CloudWatch.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records the configuration state of AWS resources over time and can show that the bucket no longer exists, but it does not capture the API event details (caller identity, IP, timestamp) the way CloudTrail does.

  • ✓

    AWS CloudTrail

    Why this is correct

    CloudTrail logs every API call to AWS services, capturing the IAM identity, source IP, timestamp, and operation details. Searching CloudTrail for DeleteBucket events would show exactly who deleted the S3 bucket, when, and from which IP.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a machine-learning-based threat detection service, not an API audit recorder. It continuously consumes CloudTrail management events, VPC Flow Logs, and DNS logs to detect anomalies such as compromised credentials or unusual S3 access patterns. While it may flag suspicious activity related to a bucket deletion, it relies on CloudTrail's audit records as a data source and cannot serve as the authoritative queryable history of who performed the DeleteBucket call.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.