DVA-C02 Security Practice Question
A developer is designing a system that must meet PCI DSS compliance. Which THREE AWS services can help with logging and monitoring security events?
⚠ Common exam trap
Test-takers frequently confuse VPC Flow Logs (network metadata) with security event logging, or mistakenly think KMS is a logging service because it is used for encryption, but neither generates or monitors security events as required by PCI DSS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Logs
Amazon CloudWatch Logs is correct because it provides a centralized service for collecting, monitoring, and storing log data from various AWS resources and applications. For PCI DSS compliance, CloudWatch Logs can ingest security-related logs (e.g., from EC2, Lambda, or on-premises servers) and enable real-time monitoring, metric filters, and alarms to detect and respond to security events. It also supports log retention policies and encryption at rest using AWS KMS, which are required for audit trails under PCI DSS Requirement 10.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon CloudWatch Logs
Why this is correct
Amazon CloudWatch Logs provides a scalable and centralized service for ingesting, storing, and analyzing logs from various sources, including EC2 instances, Lambda functions, and custom applications. This service is crucial for meeting PCI DSS requirements for comprehensive audit trails, enabling the collection of system-level events, application logs, and security logs necessary for monitoring and incident response. Its ability to aggregate logs from disparate sources into a single, queryable repository significantly aids in demonstrating compliance with logging and monitoring mandates.
- ✗
Amazon VPC Flow Logs
Why it's wrong here
Amazon VPC Flow Logs record IP traffic going to and from network interfaces in a VPC, providing metadata like source/destination IP, port, and protocol. While useful for network troubleshooting, identifying unauthorized network access patterns, and understanding network connectivity, they do not capture detailed system-level events, application logs, or API activity. PCI DSS requires more granular logging of security events and user actions than what network flow metadata alone can provide, making Flow Logs insufficient for comprehensive compliance.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail provides a comprehensive record of actions taken by a user, role, or an AWS service in AWS, logging API calls and related events. It captures critical information such as who made the call, from what IP address, when, and what resources were affected, across your AWS accounts. This detailed audit trail is fundamental for PCI DSS compliance, enabling security teams to monitor and audit administrative activities, track changes to critical resources, and detect potential security breaches or unauthorized access attempts.
- ✗
AWS Key Management Service (KMS)
Why it's wrong here
AWS Key Management Service (KMS) is a managed service designed to create and control encryption keys used to encrypt data across various AWS services and within your applications. While encryption is an essential component of PCI DSS for protecting cardholder data at rest and in transit, KMS itself is not a logging, monitoring, or auditing service. It provides cryptographic operations and key management capabilities, but it does not collect, store, or analyze system or API logs required for compliance monitoring.
- ✓
AWS Config
Why this is correct
AWS Config continuously monitors and records your AWS resource configurations, allowing you to automate the evaluation of recorded configurations against desired baselines and compliance rules. It tracks changes to security groups, IAM policies, S3 bucket policies, and other critical resources, providing a historical view of configurations and their compliance status. This service is vital for PCI DSS by ensuring that resources remain compliant with security policies, detecting configuration drift, and providing auditable evidence of configuration integrity over time.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.