Courseiva
Security and Compliance →easyMultiple Choice

Log All AWS API Calls with CloudTrail

A DevOps engineer needs to ensure that all API calls made to AWS are logged for compliance. The logs must be stored in S3 for at least 7 years. Which AWS service should they use?

Quick Answer

The answer is AWS CloudTrail because it is the only service that records every API call made to your AWS account, capturing details like the identity, source IP, and timestamp, and it can deliver those logs directly to an S3 bucket for long-term storage. This meets the compliance requirement to retain logs for at least 7 years by using S3 lifecycle policies to transition objects to cheaper storage classes like Glacier or to delete them after the specified period. On the AWS Certified DevOps Engineer Professional DOP-C02 exam, this question tests your understanding of governance and audit controls; a common trap is confusing CloudTrail with CloudWatch Logs, which captures application logs rather than API activity. Remember the mnemonic: CloudTrail tracks the trail of API calls, while CloudWatch watches metrics and logs.

⚠ Common exam trap

Candidates often confuse CloudTrail with CloudWatch Logs or AWS Config, thinking that any logging service can capture API calls, but only CloudTrail is designed specifically for auditing AWS API activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records all API calls made to AWS, including the identity, source IP, and timestamp, and can deliver log files to an S3 bucket for long-term retention. The requirement to store logs for at least 7 years aligns with CloudTrail's ability to integrate with S3 lifecycle policies for archival or deletion after a specified period.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata for network interfaces, not API call details such as identity, action or resource. They cannot satisfy the seven-year API audit requirement. They are tempting because they do reveal traffic to AWS endpoints, and would be correct for diagnosing connectivity or rejected connections at the network layer.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and evaluates compliance, not API activity; CloudTrail captures the API calls the stem requires. Config is tempting because it also logs to S3 and supports long retention, but its recorded data is configuration state, not the API call history compliance demands.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    CloudWatch Logs stores application and service log events, not the account-wide API call audit trail; CloudTrail is the service that records API activity. CloudWatch Logs is tempting because it can export to S3 with long retention, but it lacks the API-call scope the compliance requirement specifies.

  • ✓

    AWS CloudTrail

    Why this is correct

    CloudTrail records every API call across the account, including the identity, source IP and timestamp, and delivers these events to an S3 bucket. This satisfies the requirement to log all API calls, with S3 lifecycle policies retaining the logs for the mandated seven years.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to centralize logging of all API calls made within their AWS account for auditing. Which service should they use?

easy
  • A.Amazon S3 access logs
  • ✓ B.AWS CloudTrail
  • C.VPC Flow Logs
  • D.Amazon CloudWatch Logs

Why B: AWS CloudTrail is the service designed to log all API calls made within an AWS account, providing a detailed audit trail of actions taken by users, roles, and services. It records API activity across the AWS Management Console, SDKs, CLI, and other services. CloudTrail logs can be delivered to S3 and CloudWatch Logs for analysis.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.