DOP-C02 Security and Compliance Practice Question
A DevOps engineer needs to ensure that all API calls made to AWS are recorded for auditing purposes. Which AWS service should be used?
⚠ Common exam trap
A common mix-up: candidates confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which records API calls), as both are used for auditing but serve fundamentally different purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records all API calls made to AWS, including the identity of the caller, the time of the call, the source IP address, and the request parameters. This provides a complete audit trail of user activity and API usage, which is essential for auditing, security analysis, and compliance requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the correct answer because it is the native AWS service designed to record all API activity across your account. Every management event, including calls made by users, roles, or AWS services, is captured with details like the identity of the caller, source IP address, event time, request parameters, and response elements. By creating a trail, you can deliver these audit logs to an S3 bucket for long-term storage and enable CloudTrail Insights to detect anomalous API activity, which directly satisfies the requirement to ensure all API calls are audited.
- ✗
AWS Config
Why it's wrong here
AWS Config is incorrect because it does not record API calls; instead, it records the configuration state of your AWS resources and tracks changes to those configurations over time. It uses rules to evaluate whether resources comply with your desired policies (e.g., checking if an S3 bucket is public), and it maintains a configuration history and configuration snapshots. Although AWS Config may indirectly reflect the outcome of an API call (like a modified resource), it does not capture the API call itself, so it cannot provide a complete audit trail of who performed what action.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is incorrect because it is a log management service that stores, monitors, and queries log files from sources you explicitly configure, such as application logs, system logs, or AWS service logs. It does not automatically capture AWS API calls unless you separately configure CloudTrail to send its event logs to CloudWatch Logs. Even then, CloudWatch Logs is merely the destination for the events; the actual recording and API-call auditing capability resides in CloudTrail, not in CloudWatch Logs itself, so this service alone cannot fulfill the requirement.
- ✗
Amazon VPC Flow Logs
Why it's wrong here
Amazon VPC Flow Logs is incorrect because it captures IP traffic information at the network interface level, not the API call level. It records metadata about network flows, including source and destination IP addresses, ports, protocol, packet counts, and byte counts, which helps with network troubleshooting and security analysis. Flow Logs cannot identify the IAM user or service that made an API call, nor does it include the request parameters or identity context, so it is fundamentally incapable of providing an audit trail of API calls.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A DevOps engineer needs to ensure that all API calls made to AWS services are logged for auditing purposes. Which AWS service should be enabled?
easy- ✓ A.AWS CloudTrail
- B.AWS Config
- C.VPC Flow Logs
- D.Amazon CloudWatch Logs
Why A: AWS CloudTrail (option A) is the correct service because it records API calls made to AWS services for auditing, governance, and compliance. Option B (AWS Config) is used to evaluate resource configurations against desired policies, not to record API calls. Option C (VPC Flow Logs) captures network traffic information at the VPC level. Option D (Amazon CloudWatch Logs) is a service for storing and monitoring log files from various sources, but does not itself record API calls.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.