Courseiva
Security →mediumMultiple Select

DVA-C02 Security Practice Question

A developer is designing a system that must meet PCI DSS compliance. Which THREE AWS services can help with logging and monitoring security events?

⚠ Common exam trap

Test-takers frequently confuse VPC Flow Logs (network metadata) with security event logging, or mistakenly think KMS is a logging service because it is used for encryption, but neither generates or monitors security events as required by PCI DSS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Logs

Amazon CloudWatch Logs is correct because it provides a centralized service for collecting, monitoring, and storing log data from various AWS resources and applications. For PCI DSS compliance, CloudWatch Logs can ingest security-related logs (e.g., from EC2, Lambda, or on-premises servers) and enable real-time monitoring, metric filters, and alarms to detect and respond to security events. It also supports log retention policies and encryption at rest using AWS KMS, which are required for audit trails under PCI DSS Requirement 10.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    Amazon CloudWatch Logs provides a scalable and centralized service for ingesting, storing, and analyzing logs from various sources, including EC2 instances, Lambda functions, and custom applications. This service is crucial for meeting PCI DSS requirements for comprehensive audit trails, enabling the collection of system-level events, application logs, and security logs necessary for monitoring and incident response. Its ability to aggregate logs from disparate sources into a single, queryable repository significantly aids in demonstrating compliance with logging and monitoring mandates.

  • ✗

    Amazon VPC Flow Logs

    Why it's wrong here

    Amazon VPC Flow Logs record IP traffic going to and from network interfaces in a VPC, providing metadata like source/destination IP, port, and protocol. While useful for network troubleshooting, identifying unauthorized network access patterns, and understanding network connectivity, they do not capture detailed system-level events, application logs, or API activity. PCI DSS requires more granular logging of security events and user actions than what network flow metadata alone can provide, making Flow Logs insufficient for comprehensive compliance.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail provides a comprehensive record of actions taken by a user, role, or an AWS service in AWS, logging API calls and related events. It captures critical information such as who made the call, from what IP address, when, and what resources were affected, across your AWS accounts. This detailed audit trail is fundamental for PCI DSS compliance, enabling security teams to monitor and audit administrative activities, track changes to critical resources, and detect potential security breaches or unauthorized access attempts.

  • ✗

    AWS Key Management Service (KMS)

    Why it's wrong here

    AWS Key Management Service (KMS) is a managed service designed to create and control encryption keys used to encrypt data across various AWS services and within your applications. While encryption is an essential component of PCI DSS for protecting cardholder data at rest and in transit, KMS itself is not a logging, monitoring, or auditing service. It provides cryptographic operations and key management capabilities, but it does not collect, store, or analyze system or API logs required for compliance monitoring.

  • ✓

    AWS Config

    Why this is correct

    AWS Config continuously monitors and records your AWS resource configurations, allowing you to automate the evaluation of recorded configurations against desired baselines and compliance rules. It tracks changes to security groups, IAM policies, S3 bucket policies, and other critical resources, providing a historical view of configurations and their compliance status. This service is vital for PCI DSS by ensuring that resources remain compliant with security policies, detecting configuration drift, and providing auditable evidence of configuration integrity over time.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.