SCS-C02 Management and Security Governance Practice Question
A company needs to audit all changes to IAM policies in their AWS account for compliance. Which AWS service should be enabled to record the API calls that modify IAM policies?
⚠ Common exam trap
SCS-C02 often tests the difference between CloudTrail (who did what API call) and AWS Config (what the resource configuration was) — candidates confuse 'audit API calls' with 'track configuration changes' and pick AWS Config.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail records API activity in an AWS account, including all calls that modify IAM policies such as CreatePolicy, PutRolePolicy, AttachRolePolicy, and DeletePolicy. Enabling CloudTrail (which is on by default for management events) provides the audit trail of who made the change, when, and from where. This is the correct service for auditing IAM policy modifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
CloudWatch Logs captures log data from applications and AWS services but does not natively record IAM API calls; AWS CloudTrail is the service that logs all IAM policy changes via its management event trail. This option tempts because CloudWatch Logs can store and monitor CloudTrail logs if configured as a destination, leading one to assume it directly records the calls, whereas the actual recording requires CloudTrail to be enabled first.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configurations and tracks changes over time as configuration items, but it does not capture the API call history that caused those changes. For IAM policies, Config can show the final or previous policy documents and evaluate them against rules, yet it cannot reveal who invoked the change, from where, or via which API operation. Auditing all changes requires the control-plane event history that only CloudTrail provides.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the native service that records management events in the AWS control plane, including every IAM policy change such as PutRolePolicy, AttachUserPolicy, and DeletePolicy. Each event includes the requesting principal, source IP, timestamp, and request/response details, giving you a complete audit trail. You can configure a trail to deliver these logs to S3 or CloudWatch Logs for long-term storage, analysis, and alerting on unauthorized IAM modifications.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic that passes to and from network interfaces within a VPC, such as source and destination addresses, ports, protocol, and packet/byte counts. They operate at the data plane and cannot record IAM policy changes, which are API calls made to the AWS control plane and not represented as network flows. Flow logs help with network troubleshooting and security analysis, but they are irrelevant for auditing identity and access management modifications.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.