DOP-C02 Security and Compliance Practice Question
A company wants to ensure that all API calls made within its AWS account are logged for auditing purposes. Which AWS service should be enabled to meet this requirement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the service that records API activity in an AWS account, making it the correct choice. Option A is incorrect because AWS Config tracks resource configuration changes, not API calls. Option C is incorrect because CloudWatch Logs is for log storage and monitoring, not for recording API calls. Option D is incorrect because VPC Flow Logs capture network traffic, not API calls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config is designed to record and evaluate resource configuration changes over time, not the underlying API calls that triggered those changes. While Config can use CloudTrail log delivery to detect changes, it does not itself capture who made the call, the request parameters, or the response. Therefore it cannot serve as the authoritative audit log for all API activity.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the native auditing service that records every API call made in the account, including calls from the console, SDKs, CLI, and other AWS services. Each event captures the identity of the caller, source IP, time, request and response elements, and the specific action invoked. This makes CloudTrail the correct and only service in this list that directly provides a complete API call history for auditing.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a log aggregation and monitoring service, but it does not capture or record AWS API calls by default. To get API call data into CloudWatch Logs, you must explicitly configure CloudTrail to deliver its event logs to a CloudWatch Logs log group. Without that integration, CloudWatch Logs only stores application, system, and custom logs you send to it, not the API call records itself.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic passing through network interfaces, such as source/destination addresses, ports, protocol, and packet counts. They operate at layer 3/4 and do not inspect application-layer payloads or include AWS identity information, request bodies, or which principal made the call. Thus they are useful for network diagnostics but cannot provide an audit trail of API calls.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.