Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company's security team requires that all API calls to AWS are logged for audit purposes. Which service should be enabled to capture and store these logs?

⚠ Common exam trap

Many candidates confuse CloudWatch Logs with CloudTrail because both involve 'logging', but CloudWatch Logs is for application and system logs (e.g., from EC2 or Lambda), while CloudTrail is exclusively for AWS API call logs, and the question explicitly asks for 'API calls to AWS'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it is specifically designed to log all API calls made to the AWS environment, including calls made via the AWS Management Console, AWS SDKs, command line tools, and higher-level AWS services. CloudTrail captures the identity of the caller, the time of the call, the source IP address, the request parameters, and the response elements, storing this information in a log file that can be delivered to an Amazon S3 bucket for long-term audit storage. This directly meets the security team's requirement to capture and store all API calls for audit purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the governance, compliance, and audit service that continuously logs every API call made to AWS across the entire account. Each event records the caller identity, source IP address, request parameters, and response elements, which directly satisfies the security team's requirement to audit all API activity. CloudTrail can also deliver these immutable audit logs to an S3 bucket or CloudWatch Logs for long-term retention and automated analysis. It is the definitive service for answering who, what, and when regarding AWS API usage.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is designed to ingest, store, and monitor log data generated by your applications, such as application logs, system logs from EC2 instances, and Lambda function execution logs. It does not itself record AWS API calls, because it is a log management service rather than an audit trail service. While CloudTrail can be configured to send its API events to CloudWatch Logs, that integration consumes events from CloudTrail; CloudWatch Logs has no native capability to capture API calls on its own. Relying on CloudWatch Logs alone would leave the security team blind to API activity.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a configuration management service that records the configuration state of AWS resources and tracks how those configurations change over time, such as an EC2 instance's instance type or a security group's ingress rules. It evaluates these recorded configurations against compliance rules but does not log the API calls that initiated the changes, nor does it capture the identity of the principal who made the call. This makes it unsuitable for an API audit requirement because it focuses on what a resource looks like, not the operational actions taken against it. To achieve the security team's goal, you need an event-level audit trail, which AWS Config cannot provide.

  • ✗

    Amazon VPC Flow Logs

    Why it's wrong here

    Amazon VPC Flow Logs capture metadata about IP network traffic that traverses your VPC, including each flow's source and destination IP addresses, ports, protocol, and packet/byte counts. They are fundamentally a network telemetry tool, intended for traffic analysis, threat detection, and troubleshooting connectivity, not for logging management-plane API requests. Flow Logs do not contain any information about API callers, API requests, or the AWS service operations invoked, so they cannot satisfy the security team's requirement to audit all API calls. Such audit data belongs in the control plane, not the data plane that Flow Logs observe.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.