DOP-C02 Security and Compliance Practice Question
A company wants to audit all changes to IAM policies in their AWS account. Which THREE services can be used to capture and alert on IAM policy changes? (Choose THREE.)
⚠ Common exam trap
DOP-C02 often tests service-role confusion — candidates pick Inspector or Trusted Advisor for 'audit/alert' questions because they sound security-related, but only Config, CloudTrail, and EventBridge actually capture and act on IAM change events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is correct because it continuously records resource configuration changes, including IAM policy changes, and can evaluate them against rules or configuration snapshots to detect and audit modifications. AWS CloudTrail is correct because it logs all API activity in the account, including IAM policy creation, modification, and deletion events (e.g., CreatePolicy, PutRolePolicy, AttachRolePolicy), providing the authoritative audit trail. Amazon EventBridge is correct because it can receive CloudTrail management events and match IAM policy change events via event patterns, then route them to targets such as SNS or Lambda for alerting. AWS Trusted Advisor is not correct because it provides best-practice checks and recommendations, not a change audit or alerting mechanism for IAM policies. Amazon Inspector is not correct because it is a vulnerability management service that scans EC2 instances, container images, and Lambda functions, and does not capture IAM policy changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config
Why this is correct
AWS Config records configuration items for AWS::IAM::Policy and related resources, building a configuration history that shows exactly how IAM policy documents changed over time. It evaluates those configurations against custom or managed rules to detect noncompliant policies. This provides a persistent, queryable state timeline, which is the definitive way to audit all IAM policy changes after the fact.
- ✓
AWS CloudTrail
Why this is correct
CloudTrail delivers an audit log of every IAM API call, including actions such as CreatePolicy, PutRolePolicy, and AttachUserPolicy. Each event contains the requesting principal, source IP, request parameters, and response elements, so you can trace exactly who invoked a change and when. However, CloudTrail on its own captures only the JSON of the API request and response; it does not evaluate the resulting policy configuration for compliance or maintain a state history.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor is a recommendation service that runs periodic checks against your account for cost optimization, performance, security, and fault tolerance, such as whether the root account has MFA enabled. Its IAM-related checks provide current-state best-practice flags, but it does not record a chronological history of IAM policy changes or expose the details of each modification. Thus, it cannot serve as an audit trail for policy changes.
- ✓
Amazon EventBridge
Why this is correct
Amazon EventBridge can ingest IAM API call events from CloudTrail and use event rules to match specific actions like PutUserPolicy or DeletePolicy, then invoke targets such as Lambda, SNS, or SQS for real-time alerting or automated remediation. This gives you immediate visibility into policy changes as they occur and can forward them to a durable store. But EventBridge does not persist the configuration history itself; it is a routing and event processing layer, not a change auditing repository.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that performs automated security assessments of EC2 instances and container images, checking for CVEs and unintended network exposure. It has no instrumentation to observe IAM policy definitions or monitor changes to identity permissions, and it does not produce an audit log of configuration changes. Therefore, Inspector is entirely irrelevant to auditing IAM policy modifications.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company needs to audit all changes to IAM policies in their AWS account. Which services can be used to track and log these changes? (Select TWO.)
medium- A.Amazon S3
- B.Amazon CloudWatch Logs
- ✓ C.AWS Config
- ✓ D.AWS CloudTrail
- E.Amazon GuardDuty
Why C: AWS CloudTrail logs API calls, including IAM policy changes. AWS Config can track configuration changes to IAM resources. CloudWatch Logs stores logs but does not track changes itself. GuardDuty is for threat detection. S3 is storage.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.