DOP-C02 Security and Compliance Practice Question
An organization needs to audit all AWS API calls made in their account for compliance purposes. Which AWS service should they enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail records API activity for auditing and compliance. Option A (Amazon CloudWatch Logs) is incorrect as it is a log management service but does not record API calls. Option B (AWS Config) is incorrect because it tracks resource configuration changes, not API calls. Option D (Amazon GuardDuty) is incorrect because it is a threat detection service, not a comprehensive API audit trail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a centralized service for collecting, monitoring, and storing log data from applications and AWS resources, such as EC2 instance logs or application logs. It does not have native visibility into AWS control-plane operations, so it cannot capture or record API calls made against AWS services. While you can manually send CloudTrail events to CloudWatch Logs as a downstream destination, CloudWatch Logs itself is not the source of audit trail data and therefore fails the requirement to audit all AWS API calls.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service that assesses, audits, and evaluates the configuration state of your AWS resources against desired policies. It records configuration changes and provides a timeline of resource configurations, but it does not log the API actions that caused those changes. For example, AWS Config can show that a security group rule changed, but it cannot tell you who made the ChangeIpPermission API call or when the call was made. AWS Config is designed for compliance and resource drift detection, not for API-level auditing.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the native AWS service that records every API call made in your account, including the identity of the caller, the time of the call, the source IP address, the request parameters, and the response elements. It captures management events for control-plane operations across AWS services, and can also log data events for S3 object-level activity and Lambda function invocations. CloudTrail delivers these logs to an S3 bucket (and optionally CloudWatch Logs) for long-term storage and analysis, making it the correct service for auditing all AWS API calls.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior using machine learning, anomaly detection, and integrated threat intelligence feeds. It analyzes CloudTrail event logs, VPC flow logs, and DNS logs to identify indicators of compromise, but it does not generate or store a complete audit trail of API calls. GuardDuty consumes API-call data to detect threats, not to serve as an audit log itself, so it is not suitable for the organization's auditing requirement.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company wants to ensure that all API calls made within its AWS account are logged for auditing purposes. Which AWS service should be enabled to meet this requirement?
easy- A.AWS Config
- ✓ B.AWS CloudTrail
- C.Amazon CloudWatch Logs
- D.VPC Flow Logs
Why B: AWS CloudTrail is the service that records API activity in an AWS account, making it the correct choice. Option A is incorrect because AWS Config tracks resource configuration changes, not API calls. Option C is incorrect because CloudWatch Logs is for log storage and monitoring, not for recording API calls. Option D is incorrect because VPC Flow Logs capture network traffic, not API calls.
Variation 2. A DevOps engineer must ensure that all API calls in an AWS account are logged for compliance. The logs should be stored in an S3 bucket with server-side encryption enabled. Which two services should be used together to meet these requirements?
easy- A.AWS CloudTrail and Amazon CloudWatch Logs
- ✓ B.AWS CloudTrail and Amazon S3
- C.Amazon VPC Flow Logs and Amazon S3
- D.AWS Config and AWS CloudTrail
Why B: AWS CloudTrail is the service that records API activity in an AWS account, and it can deliver those event logs directly to an Amazon S3 bucket, where server-side encryption (SSE-S3 or SSE-KMS) can be enabled to meet the compliance requirement. This combination of CloudTrail and Amazon S3 (option B) satisfies both logging all API calls and storing them encrypted in S3. Option A is wrong because CloudWatch Logs is not the required encrypted S3 storage target for CloudTrail API logs. Option C is wrong because VPC Flow Logs capture IP traffic metadata, not API calls. Option D is wrong because AWS Config records resource configuration changes, not all API calls, and pairing it with CloudTrail does not by itself provide the encrypted S3 log storage.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.