Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company needs to audit all changes to security groups in a multi-account environment. The logs must be centrally stored and immutable. Which solution meets these requirements with minimal operational overhead?

⚠ Common exam trap

DOP-C02 often tests whether candidates conflate traffic-level logs (VPC Flow Logs) or detection findings (GuardDuty) with API-level audit logs (CloudTrail), and whether they recognize S3 Object Lock as the immutability mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail in all accounts, deliver logs to a central S3 bucket with S3 Object Lock enabled

AWS CloudTrail records all API activity, including `AuthorizeSecurityGroupIngress`, `RevokeSecurityGroupIngress`, and related security group modifications, across every account. Delivering these logs to a central S3 bucket with S3 Object Lock (WORM) enabled satisfies both the audit requirement and the immutability requirement, and CloudTrail organization trails can be enabled once at the Organizations level for minimal operational overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable VPC Flow Logs in each VPC and aggregate them in Amazon CloudWatch Logs

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata—source/destination addresses, ports, protocol, and packet/byte counts—not the IAM user, role, or API action that created or modified a security group. Since the audit requirement is to attribute every security group change to a specific principal and operation, flow logs are the wrong data source; also, aggregating them in CloudWatch Logs does not add an immutable audit trail, and logs can be modified or deleted by users with sufficient permissions.

  • ✓

    Enable AWS CloudTrail in all accounts, deliver logs to a central S3 bucket with S3 Object Lock enabled

    Why this is correct

    CloudTrail is the only service that records management-plane API events such as AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress, and CreateSecurityGroup, including the requesting IAM principal, source IP, and request parameters. Delivering those trail logs to a centralized S3 bucket with S3 Object Lock enabled in compliance mode makes each log object write-once-read-many (WORM), preventing any user—even one with administrative privileges—from altering or deleting audit evidence, which satisfies the immutability and centralized audit requirements. Additionally, enabling CloudTrail in all accounts with a single organization trail and delivering to a central bucket provides a complete, tamper-proof, cross-account audit record of every security group change.

  • ✗

    Enable Amazon GuardDuty and send findings to a central S3 bucket

    Why it's wrong here

    GuardDuty is a threat-detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail management events for suspicious activity such as crypto-mining, unauthorized port scanning, or compromised credentials; it does not purpose-built record or log every API call for auditing. While GuardDuty can detect some security group modifications as part of a broader threat scenario, it is not a complete audit trail of all changes, and sending findings to an S3 bucket simply stores alerts rather than the underlying change history, so it fails to meet the need for a full, immutable audit of every security group mutation.

  • ✗

    Enable AWS Config rules to detect security group changes and store results in a central S3 bucket

    Why it's wrong here

    AWS Config records configuration state changes and can trigger rules to detect whether a security group was changed, but it captures the new configuration and the resource's compliance state—not the API caller, the IAM identity, or the exact action that caused the change. Although you could export Config snapshots or delivery history to S3, those snapshots are mutable and lack the principal-level detail required for auditing who made each change; also Config does not provide immutability, so an admin could overwrite or delete delivery files. Thus Config shows that a change happened, but not who did it, making it insufficient for a complete audit trail.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.