SCS-C03 Security Foundations and Governance Practice Question
Which AWS service is best suited for providing a comprehensive, searchable audit trail of every API call made in an AWS account?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the definitive service for tracking user activity and API usage. By recording events as log files, it provides an immutable history of actions taken by users, roles, or services. This is a foundational governance requirement, as it allows security teams to reconstruct events during investigations, verify identity actions, and comply with regulatory requirements regarding data access and infrastructure modifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
CloudWatch Logs stores and monitors log data from applications and services. While it can receive CloudTrail logs, it is not the primary service for capturing API activity; CloudTrail is the engine that generates the events. CloudWatch is for analysis, not the initial collection of API trails.
- ✓
AWS CloudTrail
Why this is correct
CloudTrail is specifically designed to log all API calls made within an AWS account. It records the identity of the caller, the time of the call, the source IP, and the request parameters, providing a complete audit trail that is essential for security auditing and operational troubleshooting.
- ✗
AWS Config
Why it's wrong here
AWS Config tracks configuration changes to resources over time. While it records changes, it does not capture the granular API call logs necessary for a comprehensive audit of who performed an action, when, and from where, making it complementary to, but not a replacement for, CloudTrail.
- ✗
AWS Systems Manager
Why it's wrong here
Systems Manager is an operational management service used for patching, automation, and configuration of instances. It is not designed to function as an audit logging service for AWS API activities across the platform, and therefore cannot replace the functionality provided by AWS CloudTrail for security governance.
About these practice questions
This SCS-C03 question is part of Courseiva's 99-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.