Courseiva
Security and Compliance →easyMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company wants to centralize logging of all API calls made within their AWS account for auditing. Which service should they use?

⚠ Common exam trap

DOP-C02 often tests the difference between CloudTrail and other logging services, and candidates might confuse VPC Flow Logs or S3 access logs with API auditing, but the trap is not recognizing CloudTrail's scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the service designed to log all API calls made within an AWS account, providing a detailed audit trail of actions taken by users, roles, and services. It records API activity across the AWS Management Console, SDKs, CLI, and other services. CloudTrail logs can be delivered to S3 and CloudWatch Logs for analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon S3 access logs

    Why it's wrong here

    Amazon S3 access logs are bucket-level logs that capture only object-level requests (e.g., GET, PUT, DELETE) directed at a specific S3 bucket. They do not record management-plane API calls such as EC2 instance launches, IAM policy changes, or Lambda invocations. Since these logs must be individually enabled per bucket and cover only S3 data-plane activity, they cannot serve as a centralized audit of all API calls across the entire AWS account.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the native AWS service that records all management-plane API calls made by IAM users, roles, and AWS services, along with data-plane events for supported services. Each event includes the identity of the caller, the source IP address, the request parameters, and the response, enabling a complete audit trail. CloudTrail can be configured with a multi-region trail or an organization trail to centralize logging across all accounts and regions, making it the correct choice for centralized API call logging.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic entering and leaving network interfaces within a VPC, including source and destination IPs, ports, protocol, and packet counts. This operates at the network layer (L3/L4) and does not include application-layer request details such as AWS API names, IAM identities, or request parameters. Consequently, VPC Flow Logs provide no visibility into which API calls were made or by whom, making them unsuitable for logging API activity.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is a managed service for storing, monitoring, and querying log streams, but it does not generate or record AWS API calls on its own. CloudTrail can be configured to deliver events to CloudWatch Logs, but without that integration or custom application logging, CloudWatch Logs contains no API activity data. Therefore, while CloudWatch Logs may be a useful destination for storing and alerting on API-call logs, it is not the source of such logs and cannot be used as the primary service for capturing them.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A DevOps engineer needs to ensure that all API calls made to AWS are logged for compliance. The logs must be stored in S3 for at least 7 years. Which AWS service should they use?

easy
  • A.VPC Flow Logs
  • B.AWS Config
  • C.Amazon CloudWatch Logs
  • ✓ D.AWS CloudTrail

Why D: AWS CloudTrail is the correct service because it records all API calls made to AWS, including the identity, source IP, and timestamp, and can deliver log files to an S3 bucket for long-term retention. The requirement to store logs for at least 7 years aligns with CloudTrail's ability to integrate with S3 lifecycle policies for archival or deletion after a specified period.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.