Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company uses AWS CloudTrail to log management events in all regions. The security team notices that some API calls made by an IAM user are not appearing in the CloudTrail event history. What is the most likely reason?

⚠ Common exam trap

It's easy for candidates to assume missing API calls are due to configuration issues (like single-region trails or console-only access) rather than the 90-day retention limit of the event history, which is a fundamental but easily overlooked CloudTrail behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudTrail event history only retains events for 90 days; older events are not visible

D is correct because CloudTrail event history only retains the last 90 days of events. If the API calls were made more than 90 days ago, they would no longer appear in the event history, even though the trail itself may still be delivering log files to an S3 bucket for longer-term storage. The security team is likely looking at the event history rather than querying the S3 bucket or using Athena for older events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user used the AWS Management Console, not the CLI

    Why it's wrong here

    CloudTrail logs management events regardless of the client used to issue the API call; the AWS Management Console, CLI, SDKs, and other tools all generate the same underlying API requests that CloudTrail captures. Therefore, using the console rather than the CLI would still produce CloudTrail events, and the request source cannot change the 90-day retention limit of event history. The user's inability to find old events is a retention issue, not an ingestion or access-method issue.

  • ✗

    The trail is configured for a single region only

    Why it's wrong here

    A trail configured for a single region only records management events for that region, but CloudTrail's 'Event history' page is a separate account-level feature that displays events for all regions unless filtered. Even with a single-region trail, you can still view up to 90 days of event history, because the 90-day retention is fixed and independent of the trail's region scope. Thus, the regional configuration would affect what events are delivered to an S3 bucket, but it does not explain the absence of events older than 90 days.

  • ✗

    The API calls were read-only and excluded by default

    Why it's wrong here

    CloudTrail management event logging includes both read and write operations by default; the optional 'read-only' filter is used to classify events after capture, not to exclude read-only calls from logging. The CloudTrail event history page records read-only management events such as Describe* and List* calls as part of its default configuration, so these API calls are present in event history. Therefore, read-only calls cannot be the reason that events older than 90 days are missing.

  • ✓

    CloudTrail event history only retains events for 90 days; older events are not visible

    Why this is correct

    CloudTrail event history is a built-in feature that provides a view of the last 90 days of account activity, and this retention period is not configurable. Once an event is older than 90 days, it is no longer visible in event history, and the only way to retain it is to configure a trail that delivers CloudTrail log files to Amazon S3 (and optionally CloudWatch Logs) with a suitable lifecycle policy. This 90-day limit applies uniformly to all management events, regardless of the client, region scope, or whether the calls are read-only or write-only.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.