DOP-C02 Security and Compliance Practice Question
A DevOps engineer needs to ensure that all API calls made to AWS services are logged for auditing purposes. Which AWS service should be enabled?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail (option A) is the correct service because it records API calls made to AWS services for auditing, governance, and compliance. Option B (AWS Config) is used to evaluate resource configurations against desired policies, not to record API calls. Option C (VPC Flow Logs) captures network traffic information at the VPC level. Option D (Amazon CloudWatch Logs) is a service for storing and monitoring log files from various sources, but does not itself record API calls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the purpose-built service that records every API call made in your AWS account as an event, including the identity of the caller, the source IP address, the requested action, and the response returned. It supports management events, data events, and CloudTrail Insights events, and it can deliver these immutable audit logs to an S3 bucket or CloudWatch Logs for retention and analysis. As the only option that natively records API activity, CloudTrail is the correct choice for auditing all API calls.
- ✗
AWS Config
Why it's wrong here
AWS Config does not record API calls; instead, it continuously evaluates and records the configuration state of your AWS resources — such as whether an EC2 instance type is allowed or whether an S3 bucket is publicly accessible — and maintains a configuration history and relationships. While Config can help answer 'what changed in resource state' and even trigger notifications via rules, it cannot tell you who made a specific API call or which action was invoked. Its per-resource state model is fundamentally different from CloudTrail's per-action event model.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic that actually flows through your VPC network interfaces, including source and destination IP addresses, ports, protocols, packet counts, and bytes transferred. They are designed for network-level diagnostics and security analysis, such as detecting unusual traffic patterns or troubleshooting connectivity issues, but they contain no information about AWS API actions or the identities of the users who performed them. Thus, Flow Logs only reveal the network footprint, not the API activity.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a centralized log storage and monitoring service that ingests logs emitted by other AWS services, applications, and on-premises systems; it can also receive CloudTrail events if you explicitly configure a CloudTrail trail to deliver to CloudWatch Logs. However, CloudWatch Logs itself does not generate or record API calls — it only stores and helps you query log data that upstream services send to it. Using CloudWatch Logs alone would not capture any API activity, making it a destination for CloudTrail data, not a replacement for it.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.