DEA-C01 Data Security and Governance Practice Question
A data engineer needs to audit data access events in Amazon S3. Which AWS service should be used to record and monitor API calls for S3 buckets?
⚠ Common exam trap
DEA-C01 often tests the confusion between CloudTrail (API audit logging) and AWS Config (configuration compliance tracking), since both provide visibility into account activity but serve fundamentally different purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail records API activity across AWS services, including S3 data-plane and management-plane events, capturing who made each request, from where, and when. For auditing data access to S3 buckets, CloudTrail (with S3 data events enabled) is the authoritative service. It integrates with CloudWatch Logs and S3 for long-term retention and analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail records S3 data events such as GetObject and PutObject, capturing the identity, source IP and timestamp of each API call. Enabling data-event logging on the buckets satisfies the audit requirement, which S3 server access logs alone cannot match for API-level detail.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configuration changes and evaluates compliance against rules; it does not log individual S3 API calls, which CloudTrail data events capture. Config is tempting because it audits S3 bucket settings such as public access and encryption, and would be correct for configuration-compliance auditing rather than access-event auditing.
- ✗
Amazon Macie
Why it's wrong here
Macie discovers and classifies sensitive data in S3 using machine learning; it does not record API call events, which CloudTrail data events capture. Macie is tempting because it targets S3 specifically, and would be correct when the requirement is identifying personally identifiable information rather than auditing access.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty detects malicious activity and anomalous behaviour using threat intelligence; it does not record S3 API call events, which CloudTrail data events capture. GuardDuty is tempting because it surfaces suspicious S3 access, and would be correct for threat detection rather than providing the audit trail itself.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.