DOP-C02 Security and Compliance Practice Question
A DevOps engineer is tasked with auditing all AWS API calls made in the account for compliance purposes. The engineer needs to ensure that the audit logs are tamper-proof and stored cost-effectively. Which TWO services should the engineer use?
⚠ Common exam trap
DOP-C02 often tests the distinction between CloudTrail (audit trail) and Config (configuration compliance), and between CloudWatch Logs (aggregation) and S3 Object Lock (immutability), tricking candidates into picking Config or CloudWatch for tamper-proof audit storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail (B) is correct because it is the service that records all AWS API activity in an account as event logs, which is exactly what is needed to audit API calls for compliance. Amazon S3 with Object Lock enabled (C) is correct because CloudTrail delivers its logs to an S3 bucket, and S3 Object Lock provides WORM (write-once-read-many) protection so the logs cannot be altered or deleted, while S3 storage classes keep the cost low for long-term retention. AWS Config (A) is not correct because it records resource configuration changes and compliance state, not the full set of API calls. Amazon CloudWatch Logs (D) is not correct because it is a log storage and monitoring service, not the API audit trail itself, and it lacks the immutable WORM guarantee. AWS KMS (E) is not correct because it provides encryption key management, which supports security but does not by itself create tamper-proof, cost-effective audit logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config monitors and records the history of resource configuration changes — such as a security group rule change or an EBS volume attachment — and evaluates those changes against compliance rules. It does not capture who performed each API call, the request parameters, or the source IP address, and it lacks a WORM storage mechanism for its configuration history. Thus AWS Config provides configuration compliance but no tamper-evident audit trail of API activity.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the principal service that logs all management, data, and insight API calls across an AWS account, capturing identity, request context, and response details. It is correct for this scenario because you need API-call logging, but to make the resulting log files truly tamper-proof you must configure CloudTrail to deliver them to an S3 bucket with Object Lock enabled. CloudTrail also supports log file integrity validation, yet that only detects tampering, whereas Object Lock prevents it.
- ✓
Amazon S3 with Object Lock enabled
Why this is correct
Amazon S3 with Object Lock enabled stores CloudTrail delivery logs in Write-Once-Read-Many (WORM) mode, making them immutable. This prevents any user — including the root account — from modifying or deleting the logs, which is essential for a tamper-proof audit trail. Governance and Compliance retention modes (and legal holds) enforce retention policies even after a bucket policy changes, satisfying compliance regimes that mandate unalterable audit records.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a service for capturing application, system, and service logs, not a native recorder of AWS API calls. Although CloudTrail can stream events to CloudWatch Logs, the log groups themselves do not offer WORM/object-lock protections, so logs can be edited or purged by anyone with sufficient IAM permissions. Without immutable storage backing, CloudTrail events in CloudWatch Logs are not tamper-proof and therefore do not alone satisfy an audit requirement.
- ✗
AWS KMS
Why it's wrong here
AWS KMS is a key management and encryption service that can encrypt CloudTrail log files at rest using server-side encryption, but it does not record API activity or preserve data integrity. Encryption protects confidentiality; it does not stop an attacker with delete or put permissions from altering or replacing the logs. KMS has no concept of WORM or immutability, so it cannot be the mechanism that makes an audit trail tamper-proof.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization needs to audit all AWS API calls made in their account for compliance purposes. Which AWS service should they enable?
easy- A.Amazon CloudWatch Logs
- B.AWS Config
- ✓ C.AWS CloudTrail
- D.Amazon GuardDuty
Why C: AWS CloudTrail records API activity for auditing and compliance. Option A (Amazon CloudWatch Logs) is incorrect as it is a log management service but does not record API calls. Option B (AWS Config) is incorrect because it tracks resource configuration changes, not API calls. Option D (Amazon GuardDuty) is incorrect because it is a threat detection service, not a comprehensive API audit trail.
Variation 2. A company wants to ensure that all API calls made within its AWS account are logged for auditing purposes. Which AWS service should be enabled to meet this requirement?
easy- A.AWS Config
- ✓ B.AWS CloudTrail
- C.Amazon CloudWatch Logs
- D.VPC Flow Logs
Why B: AWS CloudTrail is the service that records API activity in an AWS account, making it the correct choice. Option A is incorrect because AWS Config tracks resource configuration changes, not API calls. Option C is incorrect because CloudWatch Logs is for log storage and monitoring, not for recording API calls. Option D is incorrect because VPC Flow Logs capture network traffic, not API calls.
Variation 3. A DevOps engineer must ensure that all API calls in an AWS account are logged for compliance. The logs should be stored in an S3 bucket with server-side encryption enabled. Which two services should be used together to meet these requirements?
easy- A.AWS CloudTrail and Amazon CloudWatch Logs
- ✓ B.AWS CloudTrail and Amazon S3
- C.Amazon VPC Flow Logs and Amazon S3
- D.AWS Config and AWS CloudTrail
Why B: AWS CloudTrail is the service that records API activity in an AWS account, and it can deliver those event logs directly to an Amazon S3 bucket, where server-side encryption (SSE-S3 or SSE-KMS) can be enabled to meet the compliance requirement. This combination of CloudTrail and Amazon S3 (option B) satisfies both logging all API calls and storing them encrypted in S3. Option A is wrong because CloudWatch Logs is not the required encrypted S3 storage target for CloudTrail API logs. Option C is wrong because VPC Flow Logs capture IP traffic metadata, not API calls. Option D is wrong because AWS Config records resource configuration changes, not all API calls, and pairing it with CloudTrail does not by itself provide the encrypted S3 log storage.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.