Courseiva
Security and Compliance →mediumMultiple Select

DOP-C02 Security and Compliance Practice Question

A company wants to audit all changes to IAM policies in their AWS account. Which THREE services can be used to capture and alert on IAM policy changes? (Choose THREE.)

⚠ Common exam trap

DOP-C02 often tests service-role confusion — candidates pick Inspector or Trusted Advisor for 'audit/alert' questions because they sound security-related, but only Config, CloudTrail, and EventBridge actually capture and act on IAM change events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config is correct because it continuously records resource configuration changes, including IAM policy changes, and can evaluate them against rules or configuration snapshots to detect and audit modifications. AWS CloudTrail is correct because it logs all API activity in the account, including IAM policy creation, modification, and deletion events (e.g., CreatePolicy, PutRolePolicy, AttachRolePolicy), providing the authoritative audit trail. Amazon EventBridge is correct because it can receive CloudTrail management events and match IAM policy change events via event patterns, then route them to targets such as SNS or Lambda for alerting. AWS Trusted Advisor is not correct because it provides best-practice checks and recommendations, not a change audit or alerting mechanism for IAM policies. Amazon Inspector is not correct because it is a vulnerability management service that scans EC2 instances, container images, and Lambda functions, and does not capture IAM policy changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Config

    Why this is correct

    AWS Config records configuration items for AWS::IAM::Policy and related resources, building a configuration history that shows exactly how IAM policy documents changed over time. It evaluates those configurations against custom or managed rules to detect noncompliant policies. This provides a persistent, queryable state timeline, which is the definitive way to audit all IAM policy changes after the fact.

  • ✓

    AWS CloudTrail

    Why this is correct

    CloudTrail delivers an audit log of every IAM API call, including actions such as CreatePolicy, PutRolePolicy, and AttachUserPolicy. Each event contains the requesting principal, source IP, request parameters, and response elements, so you can trace exactly who invoked a change and when. However, CloudTrail on its own captures only the JSON of the API request and response; it does not evaluate the resulting policy configuration for compliance or maintain a state history.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is a recommendation service that runs periodic checks against your account for cost optimization, performance, security, and fault tolerance, such as whether the root account has MFA enabled. Its IAM-related checks provide current-state best-practice flags, but it does not record a chronological history of IAM policy changes or expose the details of each modification. Thus, it cannot serve as an audit trail for policy changes.

  • ✓

    Amazon EventBridge

    Why this is correct

    Amazon EventBridge can ingest IAM API call events from CloudTrail and use event rules to match specific actions like PutUserPolicy or DeletePolicy, then invoke targets such as Lambda, SNS, or SQS for real-time alerting or automated remediation. This gives you immediate visibility into policy changes as they occur and can forward them to a durable store. But EventBridge does not persist the configuration history itself; it is a routing and event processing layer, not a change auditing repository.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that performs automated security assessments of EC2 instances and container images, checking for CVEs and unintended network exposure. It has no instrumentation to observe IAM policy definitions or monitor changes to identity permissions, and it does not produce an audit log of configuration changes. Therefore, Inspector is entirely irrelevant to auditing IAM policy modifications.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company needs to audit all changes to IAM policies in their AWS account. Which services can be used to track and log these changes? (Select TWO.)

medium
  • A.Amazon S3
  • B.Amazon CloudWatch Logs
  • ✓ C.AWS Config
  • ✓ D.AWS CloudTrail
  • E.Amazon GuardDuty

Why C: AWS CloudTrail logs API calls, including IAM policy changes. AWS Config can track configuration changes to IAM resources. CloudWatch Logs stores logs but does not track changes itself. GuardDuty is for threat detection. S3 is storage.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.