Question 756 of 1,511
DOP-C02 Security and Compliance Practice Question
An organization needs to audit all AWS API calls made in their account for compliance purposes. Which AWS service should they enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail records API activity for auditing and compliance. Option A (Amazon CloudWatch Logs) is incorrect as it is a log management service but does not record API calls. Option B (AWS Config) is incorrect because it tracks resource configuration changes, not API calls. Option D (Amazon GuardDuty) is incorrect because it is a threat detection service, not a comprehensive API audit trail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
CloudWatch Logs can store logs but does not record API calls.
- ✗
AWS Config
Why it's wrong here
Tracks resource configuration, not API calls.
- ✓
AWS CloudTrail
Why this is correct
Records API calls for auditing.
- ✗
Amazon GuardDuty
Why it's wrong here
Threat detection, not audit logging.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company wants to ensure that all API calls made within its AWS account are logged for auditing purposes. Which AWS service should be enabled to meet this requirement?
easy- A.AWS Config
- ✓ B.AWS CloudTrail
- C.Amazon CloudWatch Logs
- D.VPC Flow Logs
Why B: AWS CloudTrail is the service that records API activity in an AWS account, making it the correct choice. Option A is incorrect because AWS Config tracks resource configuration changes, not API calls. Option C is incorrect because CloudWatch Logs is for log storage and monitoring, not for recording API calls. Option D is incorrect because VPC Flow Logs capture network traffic, not API calls.
Variation 2. A DevOps engineer must ensure that all API calls in an AWS account are logged for compliance. The logs should be stored in an S3 bucket with server-side encryption enabled. Which two services should be used together to meet these requirements?
easy- A.AWS CloudTrail and Amazon CloudWatch Logs
- ✓ B.AWS CloudTrail and Amazon S3
- C.Amazon VPC Flow Logs and Amazon S3
- D.AWS Config and AWS CloudTrail
Why B: AWS CloudTrail logs all API calls in the account and can deliver these logs to an S3 bucket, where server-side encryption (SSE) can be enabled for compliance. Option A (AWS CloudTrail and Amazon CloudWatch Logs) can capture API calls, but the requirement is to store logs in an S3 bucket with encryption, not CloudWatch Logs. Option C (Amazon VPC Flow Logs and Amazon S3) captures network traffic, not API calls. Option D (AWS Config and AWS CloudTrail) includes AWS Config, which tracks resource configuration changes, not API calls; CloudTrail alone suffices for API logging, but Config is not needed for this requirement.
Last reviewed: Jun 20, 2026
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.