Courseiva

DEA-C01 Data Security and Governance Practice Question

A company stores sensitive financial data in Amazon S3 and requires that all data be encrypted at rest using customer-managed keys. A data engineer configures the S3 bucket to use SSE-KMS with a customer-managed KMS key. The security team now wants to audit all API calls that use the KMS key to decrypt data. Which AWS service should the engineer use to capture and review these KMS API calls?

⚠ Common exam trap

The trap here is assuming that AWS Config or CloudWatch Logs automatically capture API calls, when actually CloudTrail is the dedicated service for API auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the service that records API activity in your AWS account, including KMS operations. By enabling CloudTrail, you can audit who used the KMS key and when. AWS Config, CloudWatch Logs, and Trusted Advisor do not provide the same level of API call logging for KMS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records configuration changes to resources, not API calls. While it can track changes to KMS key policies, it does not log individual Decrypt or Encrypt operations. Therefore, it cannot provide the detailed audit trail of KMS API usage required.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    Trusted Advisor provides recommendations and best-practice checks but does not log or audit API calls. It cannot be used to review KMS Decrypt operations. Its focus is on cost optimization, security, fault tolerance, and service limits.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    CloudWatch Logs can store logs from various sources, but it does not natively capture KMS API calls. You would need to configure CloudTrail to send logs to CloudWatch Logs for analysis, but CloudWatch Logs alone is not the source of KMS API activity.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail logs all API activity, including KMS operations such as Decrypt, Encrypt, and GenerateDataKey. By enabling CloudTrail, the engineer can capture and review these calls for auditing. CloudTrail is the standard service for auditing API activity across AWS services.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.