Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer needs to audit data access events in Amazon S3. Which AWS service should be used to record and monitor API calls for S3 buckets?

⚠ Common exam trap

DEA-C01 often tests the confusion between CloudTrail (API audit logging) and AWS Config (configuration compliance tracking), since both provide visibility into account activity but serve fundamentally different purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail records API activity across AWS services, including S3 data-plane and management-plane events, capturing who made each request, from where, and when. For auditing data access to S3 buckets, CloudTrail (with S3 data events enabled) is the authoritative service. It integrates with CloudWatch Logs and S3 for long-term retention and analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail records S3 data events such as GetObject and PutObject, capturing the identity, source IP and timestamp of each API call. Enabling data-event logging on the buckets satisfies the audit requirement, which S3 server access logs alone cannot match for API-level detail.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and evaluates compliance against rules; it does not log individual S3 API calls, which CloudTrail data events capture. Config is tempting because it audits S3 bucket settings such as public access and encryption, and would be correct for configuration-compliance auditing rather than access-event auditing.

  • ✗

    Amazon Macie

    Why it's wrong here

    Macie discovers and classifies sensitive data in S3 using machine learning; it does not record API call events, which CloudTrail data events capture. Macie is tempting because it targets S3 specifically, and would be correct when the requirement is identifying personally identifiable information rather than auditing access.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty detects malicious activity and anomalous behaviour using threat intelligence; it does not record S3 API call events, which CloudTrail data events capture. GuardDuty is tempting because it surfaces suspicious S3 access, and would be correct for threat detection rather than providing the audit trail itself.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.