DOP-C02 Security and Compliance Practice Question
A company's security team requires that all API calls to AWS are logged for audit purposes. Which service should be enabled to capture and store these logs?
⚠ Common exam trap
Many candidates confuse CloudWatch Logs with CloudTrail because both involve 'logging', but CloudWatch Logs is for application and system logs (e.g., from EC2 or Lambda), while CloudTrail is exclusively for AWS API call logs, and the question explicitly asks for 'API calls to AWS'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it is specifically designed to log all API calls made to the AWS environment, including calls made via the AWS Management Console, AWS SDKs, command line tools, and higher-level AWS services. CloudTrail captures the identity of the caller, the time of the call, the source IP address, the request parameters, and the response elements, storing this information in a log file that can be delivered to an Amazon S3 bucket for long-term audit storage. This directly meets the security team's requirement to capture and store all API calls for audit purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the governance, compliance, and audit service that continuously logs every API call made to AWS across the entire account. Each event records the caller identity, source IP address, request parameters, and response elements, which directly satisfies the security team's requirement to audit all API activity. CloudTrail can also deliver these immutable audit logs to an S3 bucket or CloudWatch Logs for long-term retention and automated analysis. It is the definitive service for answering who, what, and when regarding AWS API usage.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is designed to ingest, store, and monitor log data generated by your applications, such as application logs, system logs from EC2 instances, and Lambda function execution logs. It does not itself record AWS API calls, because it is a log management service rather than an audit trail service. While CloudTrail can be configured to send its API events to CloudWatch Logs, that integration consumes events from CloudTrail; CloudWatch Logs has no native capability to capture API calls on its own. Relying on CloudWatch Logs alone would leave the security team blind to API activity.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration management service that records the configuration state of AWS resources and tracks how those configurations change over time, such as an EC2 instance's instance type or a security group's ingress rules. It evaluates these recorded configurations against compliance rules but does not log the API calls that initiated the changes, nor does it capture the identity of the principal who made the call. This makes it unsuitable for an API audit requirement because it focuses on what a resource looks like, not the operational actions taken against it. To achieve the security team's goal, you need an event-level audit trail, which AWS Config cannot provide.
- ✗
Amazon VPC Flow Logs
Why it's wrong here
Amazon VPC Flow Logs capture metadata about IP network traffic that traverses your VPC, including each flow's source and destination IP addresses, ports, protocol, and packet/byte counts. They are fundamentally a network telemetry tool, intended for traffic analysis, threat detection, and troubleshooting connectivity, not for logging management-plane API requests. Flow Logs do not contain any information about API callers, API requests, or the AWS service operations invoked, so they cannot satisfy the security team's requirement to audit all API calls. Such audit data belongs in the control plane, not the data plane that Flow Logs observe.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.