An organization wants to audit all API calls made to AWS services for compliance. Which AWS service should be used to capture and store these API calls?
AWS CloudTrail records every API call to AWS services as an event, capturing the caller identity, timestamp, source IP and request details, then delivering logs to Amazon S3 for retention. This directly satisfies the compliance audit requirement to capture and store all API activity across the account.
Why this answer
AWS CloudTrail records API activity across AWS services, capturing who made each call, from which IP, when, and with what parameters, and delivers the events to S3 and/or CloudWatch Logs for auditing. It is the canonical service for compliance auditing of API calls. AWS Config, VPC Flow Logs, and CloudWatch Logs serve different observability purposes.
Exam trap
The trap is confusing 'audit API calls' with 'track resource configuration changes' (AWS Config) or 'capture network traffic' (VPC Flow Logs); candidates who do not distinguish control-plane API auditing from configuration history or flow telemetry pick the wrong service.
How to eliminate wrong answers
Option B is wrong because AWS Config records resource configuration state and changes over time, not the API call history itself; it answers 'what does this resource look like now and how did it change,' not 'who called this API.' Option C is wrong because VPC Flow Logs capture IP traffic metadata (source/destination, ports, bytes, accept/reject) at the ENI, subnet, or VPC level, which is network telemetry, not AWS API auditing. Option D is wrong because CloudWatch Logs is a log storage and analysis service; it can receive CloudTrail events but is not itself the audit capture mechanism, and it does not natively record API calls without CloudTrail.