SCS-C02 Security Logging and Monitoring Practice Question
A company uses AWS CloudTrail to log management events in all regions. The security team notices that some API calls made by an IAM user are not appearing in the CloudTrail event history. What is the most likely reason?
⚠ Common exam trap
It's easy for candidates to assume missing API calls are due to configuration issues (like single-region trails or console-only access) rather than the 90-day retention limit of the event history, which is a fundamental but easily overlooked CloudTrail behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudTrail event history only retains events for 90 days; older events are not visible
D is correct because CloudTrail event history only retains the last 90 days of events. If the API calls were made more than 90 days ago, they would no longer appear in the event history, even though the trail itself may still be delivering log files to an S3 bucket for longer-term storage. The security team is likely looking at the event history rather than querying the S3 bucket or using Athena for older events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user used the AWS Management Console, not the CLI
Why it's wrong here
CloudTrail logs management events regardless of the client used to issue the API call; the AWS Management Console, CLI, SDKs, and other tools all generate the same underlying API requests that CloudTrail captures. Therefore, using the console rather than the CLI would still produce CloudTrail events, and the request source cannot change the 90-day retention limit of event history. The user's inability to find old events is a retention issue, not an ingestion or access-method issue.
- ✗
The trail is configured for a single region only
Why it's wrong here
A trail configured for a single region only records management events for that region, but CloudTrail's 'Event history' page is a separate account-level feature that displays events for all regions unless filtered. Even with a single-region trail, you can still view up to 90 days of event history, because the 90-day retention is fixed and independent of the trail's region scope. Thus, the regional configuration would affect what events are delivered to an S3 bucket, but it does not explain the absence of events older than 90 days.
- ✗
The API calls were read-only and excluded by default
Why it's wrong here
CloudTrail management event logging includes both read and write operations by default; the optional 'read-only' filter is used to classify events after capture, not to exclude read-only calls from logging. The CloudTrail event history page records read-only management events such as Describe* and List* calls as part of its default configuration, so these API calls are present in event history. Therefore, read-only calls cannot be the reason that events older than 90 days are missing.
- ✓
CloudTrail event history only retains events for 90 days; older events are not visible
Why this is correct
CloudTrail event history is a built-in feature that provides a view of the last 90 days of account activity, and this retention period is not configurable. Once an event is older than 90 days, it is no longer visible in event history, and the only way to retain it is to configure a trail that delivers CloudTrail log files to Amazon S3 (and optionally CloudWatch Logs) with a suitable lifecycle policy. This 90-day limit applies uniformly to all management events, regardless of the client, region scope, or whether the calls are read-only or write-only.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.