DEA-C01 Data Security and Governance Practice Question
A company stores sensitive financial data in Amazon S3 and requires that all data be encrypted at rest using customer-managed keys. A data engineer configures the S3 bucket to use SSE-KMS with a customer-managed KMS key. The security team now wants to audit all API calls that use the KMS key to decrypt data. Which AWS service should the engineer use to capture and review these KMS API calls?
⚠ Common exam trap
The trap here is assuming that AWS Config or CloudWatch Logs automatically capture API calls, when actually CloudTrail is the dedicated service for API auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the service that records API activity in your AWS account, including KMS operations. By enabling CloudTrail, you can audit who used the KMS key and when. AWS Config, CloudWatch Logs, and Trusted Advisor do not provide the same level of API call logging for KMS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config records configuration changes to resources, not API calls. While it can track changes to KMS key policies, it does not log individual Decrypt or Encrypt operations. Therefore, it cannot provide the detailed audit trail of KMS API usage required.
- ✗
AWS Trusted Advisor
Why it's wrong here
Trusted Advisor provides recommendations and best-practice checks but does not log or audit API calls. It cannot be used to review KMS Decrypt operations. Its focus is on cost optimization, security, fault tolerance, and service limits.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
CloudWatch Logs can store logs from various sources, but it does not natively capture KMS API calls. You would need to configure CloudTrail to send logs to CloudWatch Logs for analysis, but CloudWatch Logs alone is not the source of KMS API activity.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail logs all API activity, including KMS operations such as Decrypt, Encrypt, and GenerateDataKey. By enabling CloudTrail, the engineer can capture and review these calls for auditing. CloudTrail is the standard service for auditing API activity across AWS services.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.