Courseiva
Security and Compliance →easyMultiple Select

DOP-C02 Security and Compliance Practice Question

A DevOps engineer is tasked with auditing all AWS API calls made in the account for compliance purposes. The engineer needs to ensure that the audit logs are tamper-proof and stored cost-effectively. Which TWO services should the engineer use?

⚠ Common exam trap

DOP-C02 often tests the distinction between CloudTrail (audit trail) and Config (configuration compliance), and between CloudWatch Logs (aggregation) and S3 Object Lock (immutability), tricking candidates into picking Config or CloudWatch for tamper-proof audit storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail (B) is correct because it is the service that records all AWS API activity in an account as event logs, which is exactly what is needed to audit API calls for compliance. Amazon S3 with Object Lock enabled (C) is correct because CloudTrail delivers its logs to an S3 bucket, and S3 Object Lock provides WORM (write-once-read-many) protection so the logs cannot be altered or deleted, while S3 storage classes keep the cost low for long-term retention. AWS Config (A) is not correct because it records resource configuration changes and compliance state, not the full set of API calls. Amazon CloudWatch Logs (D) is not correct because it is a log storage and monitoring service, not the API audit trail itself, and it lacks the immutable WORM guarantee. AWS KMS (E) is not correct because it provides encryption key management, which supports security but does not by itself create tamper-proof, cost-effective audit logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config monitors and records the history of resource configuration changes — such as a security group rule change or an EBS volume attachment — and evaluates those changes against compliance rules. It does not capture who performed each API call, the request parameters, or the source IP address, and it lacks a WORM storage mechanism for its configuration history. Thus AWS Config provides configuration compliance but no tamper-evident audit trail of API activity.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the principal service that logs all management, data, and insight API calls across an AWS account, capturing identity, request context, and response details. It is correct for this scenario because you need API-call logging, but to make the resulting log files truly tamper-proof you must configure CloudTrail to deliver them to an S3 bucket with Object Lock enabled. CloudTrail also supports log file integrity validation, yet that only detects tampering, whereas Object Lock prevents it.

  • ✓

    Amazon S3 with Object Lock enabled

    Why this is correct

    Amazon S3 with Object Lock enabled stores CloudTrail delivery logs in Write-Once-Read-Many (WORM) mode, making them immutable. This prevents any user — including the root account — from modifying or deleting the logs, which is essential for a tamper-proof audit trail. Governance and Compliance retention modes (and legal holds) enforce retention policies even after a bucket policy changes, satisfying compliance regimes that mandate unalterable audit records.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is a service for capturing application, system, and service logs, not a native recorder of AWS API calls. Although CloudTrail can stream events to CloudWatch Logs, the log groups themselves do not offer WORM/object-lock protections, so logs can be edited or purged by anyone with sufficient IAM permissions. Without immutable storage backing, CloudTrail events in CloudWatch Logs are not tamper-proof and therefore do not alone satisfy an audit requirement.

  • ✗

    AWS KMS

    Why it's wrong here

    AWS KMS is a key management and encryption service that can encrypt CloudTrail log files at rest using server-side encryption, but it does not record API activity or preserve data integrity. Encryption protects confidentiality; it does not stop an attacker with delete or put permissions from altering or replacing the logs. KMS has no concept of WORM or immutability, so it cannot be the mechanism that makes an audit trail tamper-proof.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization needs to audit all AWS API calls made in their account for compliance purposes. Which AWS service should they enable?

easy
  • A.Amazon CloudWatch Logs
  • B.AWS Config
  • ✓ C.AWS CloudTrail
  • D.Amazon GuardDuty

Why C: AWS CloudTrail records API activity for auditing and compliance. Option A (Amazon CloudWatch Logs) is incorrect as it is a log management service but does not record API calls. Option B (AWS Config) is incorrect because it tracks resource configuration changes, not API calls. Option D (Amazon GuardDuty) is incorrect because it is a threat detection service, not a comprehensive API audit trail.

Variation 2. A company wants to ensure that all API calls made within its AWS account are logged for auditing purposes. Which AWS service should be enabled to meet this requirement?

easy
  • A.AWS Config
  • ✓ B.AWS CloudTrail
  • C.Amazon CloudWatch Logs
  • D.VPC Flow Logs

Why B: AWS CloudTrail is the service that records API activity in an AWS account, making it the correct choice. Option A is incorrect because AWS Config tracks resource configuration changes, not API calls. Option C is incorrect because CloudWatch Logs is for log storage and monitoring, not for recording API calls. Option D is incorrect because VPC Flow Logs capture network traffic, not API calls.

Variation 3. A DevOps engineer must ensure that all API calls in an AWS account are logged for compliance. The logs should be stored in an S3 bucket with server-side encryption enabled. Which two services should be used together to meet these requirements?

easy
  • A.AWS CloudTrail and Amazon CloudWatch Logs
  • ✓ B.AWS CloudTrail and Amazon S3
  • C.Amazon VPC Flow Logs and Amazon S3
  • D.AWS Config and AWS CloudTrail

Why B: AWS CloudTrail is the service that records API activity in an AWS account, and it can deliver those event logs directly to an Amazon S3 bucket, where server-side encryption (SSE-S3 or SSE-KMS) can be enabled to meet the compliance requirement. This combination of CloudTrail and Amazon S3 (option B) satisfies both logging all API calls and storing them encrypted in S3. Option A is wrong because CloudWatch Logs is not the required encrypted S3 storage target for CloudTrail API logs. Option C is wrong because VPC Flow Logs capture IP traffic metadata, not API calls. Option D is wrong because AWS Config records resource configuration changes, not all API calls, and pairing it with CloudTrail does not by itself provide the encrypted S3 log storage.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.