Courseiva

DEA-C01 AWS CloudTrail Practice Question

A company wants to monitor and alert on unauthorized API calls in their AWS account. Which AWS service should be used to detect and notify on such events?

⚠ Common exam trap

Candidates often assume GuardDuty is the go-to for API call monitoring, but GuardDuty focuses on threat detection, not comprehensive API logging. CloudTrail is the correct service for logging all API calls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail and Amazon CloudWatch Events

D is correct because AWS CloudTrail records all API calls in the AWS account, and Amazon CloudWatch Events (or EventBridge) can be configured with rules to detect specific API calls (e.g., unauthorized actions) and trigger notifications. Option A is incorrect because Amazon GuardDuty and AWS Security Hub are threat detection and security management services, not primarily for monitoring all API calls. Option B is incorrect because Amazon VPC Flow Logs capture network traffic metadata, not API calls. Option C is incorrect because AWS Config monitors resource configuration changes, not API calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty and AWS Security Hub

    Why it's wrong here

    GuardDuty detects threats via anomaly and threat-intelligence findings, and Security Hub aggregates them, but neither records every API call's identity, source and outcome for alerting on unauthorised invocations. Tempting because GuardDuty does flag suspicious API activity, which suits broad threat detection rather than explicit per-call auditing.

  • ✗

    Amazon VPC Flow Logs and Amazon CloudWatch Logs

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata at the ENI, subnet or VPC level, recording accepted and rejected connections rather than CloudTrail API call identities, so unauthorised API invocations are invisible. It is tempting because flow logs do reveal rejected network traffic, which suits connectivity or port-scan troubleshooting, not API-level auditing.

  • ✗

    AWS Config and AWS Systems Manager

    Why it's wrong here

    AWS Config records resource configuration changes and Systems Manager handles operational tasks; neither detects unauthorised API activity or notifies on it. Amazon GuardDuty analyses CloudTrail management events to identify such calls. Config and Systems Manager would be correct for configuration compliance and patching respectively.

  • ✓

    AWS CloudTrail and Amazon CloudWatch Events

    Why this is correct

    CloudTrail records every API call as a management event, capturing the caller identity and whether it was authorised. CloudWatch Events (EventBridge) then matches those unauthorised-call patterns via rules and triggers notifications, satisfying the requirement to both detect and alert on unauthorised API activity.

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.