Courseiva

SCS-C02 Management and Security Governance Practice Question

A company needs to audit all changes to IAM policies in their AWS account for compliance. Which AWS service should be enabled to record the API calls that modify IAM policies?

⚠ Common exam trap

SCS-C02 often tests the difference between CloudTrail (who did what API call) and AWS Config (what the resource configuration was) — candidates confuse 'audit API calls' with 'track configuration changes' and pick AWS Config.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail records API activity in an AWS account, including all calls that modify IAM policies such as CreatePolicy, PutRolePolicy, AttachRolePolicy, and DeletePolicy. Enabling CloudTrail (which is on by default for management events) provides the audit trail of who made the change, when, and from where. This is the correct service for auditing IAM policy modifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    CloudWatch Logs captures log data from applications and AWS services but does not natively record IAM API calls; AWS CloudTrail is the service that logs all IAM policy changes via its management event trail. This option tempts because CloudWatch Logs can store and monitor CloudTrail logs if configured as a destination, leading one to assume it directly records the calls, whereas the actual recording requires CloudTrail to be enabled first.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configurations and tracks changes over time as configuration items, but it does not capture the API call history that caused those changes. For IAM policies, Config can show the final or previous policy documents and evaluate them against rules, yet it cannot reveal who invoked the change, from where, or via which API operation. Auditing all changes requires the control-plane event history that only CloudTrail provides.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the native service that records management events in the AWS control plane, including every IAM policy change such as PutRolePolicy, AttachUserPolicy, and DeletePolicy. Each event includes the requesting principal, source IP, timestamp, and request/response details, giving you a complete audit trail. You can configure a trail to deliver these logs to S3 or CloudWatch Logs for long-term storage, analysis, and alerting on unauthorized IAM modifications.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic that passes to and from network interfaces within a VPC, such as source and destination addresses, ports, protocol, and packet/byte counts. They operate at the data plane and cannot record IAM policy changes, which are API calls made to the AWS control plane and not represented as network flows. Flow logs help with network troubleshooting and security analysis, but they are irrelevant for auditing identity and access management modifications.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.