SCS-C02 Data Protection Practice Question
A company uses AWS KMS to encrypt secrets stored in AWS Secrets Manager. The security team wants to audit all KMS key usage, including attempts to use the key without proper authorization. Which AWS service should the team use to meet this requirement?
⚠ Common exam trap
SCS-C02 often tests the distinction between GuardDuty (threat detection) and CloudTrail (audit logging) — candidates pick GuardDuty thinking it audits all API calls, but it only surfaces findings, not raw audit records.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail records every API call made to KMS, including successful and failed attempts to use, encrypt, decrypt, or manage keys. Failed attempts due to insufficient permissions are logged as AccessDenied errors, giving the security team the audit trail they need. CloudTrail is the authoritative service for API-level auditing across AWS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a machine-learning-based threat detection service that consumes sources such as VPC Flow Logs, DNS query logs, and CloudTrail management events to generate security findings. It does not create or persist its own audit record of every KMS API call; instead, it may output an alert if a pattern suggests misuse, such as a compromised principal using a key from an unusual location. Because GuardDuty findings are derived and time-framed, they lack the complete queryable event history (including actor, action, and response) that a compliance audit of KMS usage requires. Thus, while GuardDuty can complement CloudTrail, it cannot replace it as the authoritative audit log.
- ✗
AWS Config
Why it's wrong here
AWS Config tracks configuration changes to resources, not API-level access attempts against a KMS key. The requirement is to audit every KMS API call—including unauthorised ones—which only AWS CloudTrail can capture by recording data-plane and control-plane events. Config is tempting because it can evaluate whether a KMS key has been rotated or has a policy allowing public access, but it cannot log a failed Decrypt request; for that compliance audit need, CloudTrail is the correct service.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the only service here that natively captures every KMS API operation as an audit event, including both management-plane calls like CreateKey and PutKeyPolicy and data-plane cryptographic calls such as Encrypt, Decrypt, and GenerateDataKey when data events are enabled. Each log entry contains the requesting IAM principal, source IP, request parameters, and response elements, and even records access-denied events from failed authorization attempts, giving security teams a complete, tamper-evident trail for compliance investigations. Because CloudTrail delivers events to an S3 bucket and optionally to CloudWatch Logs, it provides the durable, centralized audit history required by regulators, whereas the other options do not capture KMS API calls directly.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a log storage and monitoring service that only receives log records from sources that are configured to publish to it; it is not an event source that intercepts AWS KMS API calls on its own. A KMS request will never appear in CloudWatch Logs unless another service, such as a CloudTrail trail configured with a CloudWatch Logs destination, forwards it, meaning CloudWatch Logs alone cannot satisfy an audit requirement. It also does not parse or index IAM actor and KMS action fields natively, so even if logs were ingested, you would be dependent on the upstream forwarder's format and completeness. For these reasons, while CloudWatch Logs can store and alert on CloudTrail events, it is not the service that captures KMS audit events.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.