DOP-C02 Security and Compliance Practice Question
A company wants to centralize logging of all API calls made within their AWS account for auditing. Which service should they use?
⚠ Common exam trap
DOP-C02 often tests the difference between CloudTrail and other logging services, and candidates might confuse VPC Flow Logs or S3 access logs with API auditing, but the trap is not recognizing CloudTrail's scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the service designed to log all API calls made within an AWS account, providing a detailed audit trail of actions taken by users, roles, and services. It records API activity across the AWS Management Console, SDKs, CLI, and other services. CloudTrail logs can be delivered to S3 and CloudWatch Logs for analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon S3 access logs
Why it's wrong here
Amazon S3 access logs are bucket-level logs that capture only object-level requests (e.g., GET, PUT, DELETE) directed at a specific S3 bucket. They do not record management-plane API calls such as EC2 instance launches, IAM policy changes, or Lambda invocations. Since these logs must be individually enabled per bucket and cover only S3 data-plane activity, they cannot serve as a centralized audit of all API calls across the entire AWS account.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the native AWS service that records all management-plane API calls made by IAM users, roles, and AWS services, along with data-plane events for supported services. Each event includes the identity of the caller, the source IP address, the request parameters, and the response, enabling a complete audit trail. CloudTrail can be configured with a multi-region trail or an organization trail to centralize logging across all accounts and regions, making it the correct choice for centralized API call logging.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic entering and leaving network interfaces within a VPC, including source and destination IPs, ports, protocol, and packet counts. This operates at the network layer (L3/L4) and does not include application-layer request details such as AWS API names, IAM identities, or request parameters. Consequently, VPC Flow Logs provide no visibility into which API calls were made or by whom, making them unsuitable for logging API activity.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a managed service for storing, monitoring, and querying log streams, but it does not generate or record AWS API calls on its own. CloudTrail can be configured to deliver events to CloudWatch Logs, but without that integration or custom application logging, CloudWatch Logs contains no API activity data. Therefore, while CloudWatch Logs may be a useful destination for storing and alerting on API-call logs, it is not the source of such logs and cannot be used as the primary service for capturing them.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A DevOps engineer needs to ensure that all API calls made to AWS are logged for compliance. The logs must be stored in S3 for at least 7 years. Which AWS service should they use?
easy- A.VPC Flow Logs
- B.AWS Config
- C.Amazon CloudWatch Logs
- ✓ D.AWS CloudTrail
Why D: AWS CloudTrail is the correct service because it records all API calls made to AWS, including the identity, source IP, and timestamp, and can deliver log files to an S3 bucket for long-term retention. The requirement to store logs for at least 7 years aligns with CloudTrail's ability to integrate with S3 lifecycle policies for archival or deletion after a specified period.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.