SCS-C02 Management and Security Governance Practice Question
A company needs to audit all changes to IAM policies in its AWS account. Which AWS service should be used to record the change history of IAM policies?
⚠ Common exam trap
SCS-C02 often tests the distinction between AWS Config and CloudTrail: candidates may choose AWS Config because it tracks resource changes, but CloudTrail is specifically for API activity auditing, which includes the 'who, what, when, and where' of IAM policy modifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the service that records API activity in an AWS account, including all changes to IAM policies. When an IAM policy is created, modified, or deleted, CloudTrail logs the event with details such as the identity of the caller, the time of the API call, the source IP address, and the request parameters. This makes CloudTrail the authoritative source for auditing IAM policy changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a centralized log storage and monitoring service, but it does not natively capture AWS API activity such as IAM policy changes. It solely ingests and stores logs from sources like applications and AWS services; it cannot generate or record IAM change events on its own. You can configure CloudTrail to deliver events to CloudWatch Logs for real-time alerting, but that only makes CloudWatch Logs a downstream destination, not the audit source itself. Without CloudTrail integration, CloudWatch Logs provides zero visibility into IAM modifications.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that continuously analyzes AWS account activity for malicious behavior, such as unusual API calls or compromised credentials. It does not log every API request or maintain a chronological change history for IAM policies; it only generates findings when it detects suspicious or anomalous activity. Because GuardDuty focuses on identifying threats rather than recording all management events, it cannot satisfy a requirement to audit all changes to IAM policies. Relying on GuardDuty would leave most legitimate policy changes entirely undocumented.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the correct choice because it records every management event API call made in your AWS account, including all IAM policy changes such as PutRolePolicy, AttachUserPolicy, DeletePolicy, and CreatePolicy. Each event includes the identity of the caller (user, role, or service), the timestamp, source IP address, request parameters, and response elements, giving you a complete and verifiable audit trail. CloudTrail trails can deliver event logs to an Amazon S3 bucket for long-term retention and optionally to CloudWatch Logs for monitoring. This makes CloudTrail the authoritative service for auditing who changed an IAM policy, when, and what exactly was changed.
- ✗
AWS Config
Why it's wrong here
AWS Config records the configuration state of AWS resources over time and can show that an IAM policy changed from one configuration to another, but it does not capture the API call event or the identity of the principal that made the change. Config's configuration history is resource-centric and lacks the detailed request parameters, source IP, and user context that an audit log requires. While Config can help with compliance and resource drift, it is not designed to provide a full change history of API calls. For a comprehensive audit of IAM policy modifications, you need CloudTrail's event-level detail, not just Config's state-based snapshots.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.