SCS-C02 Management and Security Governance Practice Question
A company wants to log all API calls made in their AWS account for auditing. Which AWS service should be enabled to capture these logs?
⚠ Common exam trap
SCS-C02 often tests the difference between CloudTrail (API call auditing) and VPC Flow Logs (network traffic) or S3 access logs (bucket-level requests), so candidates pick a logging service that does not capture account-wide API activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail records API calls made in an AWS account, including the identity, time, source IP, and request details, which is exactly what is needed for auditing. Enabling CloudTrail captures management and, optionally, data events across services. This makes it the correct service for logging all API calls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic at the network interface level—source/destination addresses, ports, protocol, and whether packets were accepted or rejected. They provide network-level telemetry for troubleshooting connectivity and analyzing traffic patterns, but they do not include identity, request parameters, or any indication of which IAM user or service made an API call. Consequently, VPC Flow Logs cannot be used to audit API activity.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a centralized log storage, monitoring, and alerting service that will ingest log streams from sources such as applications, EC2 instances, and other AWS services. However, it is not a native source of AWS API call records; unless you configure a CloudTrail trail to deliver events to CloudWatch Logs, no API activity will appear there. Thus, CloudWatch Logs is purely a destination/aggregator, not the service that captures the API calls.
- ✗
Amazon S3 server access logs
Why it's wrong here
Amazon S3 server access logs provide detailed records of requests sent to a specific S3 bucket, including object-level operations like PUT, GET, DELETE, and the requester's identity or source IP. These logs are scoped solely to S3 API operations and do not capture calls made to other services such as EC2, IAM, Lambda, or DynamoDB. Therefore, S3 access logs are insufficient for a comprehensive audit of all API calls across the AWS environment.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the purpose-built service that records API activity across your AWS account, capturing management events for the control plane and optionally data events for services like S3. Each event includes the identity of the caller, source IP address, request parameters, response elements, and a timestamp, whether the call came from the console, SDK, or CLI. CloudTrail's event history provides 90 days of visibility by default, and you can create trails to deliver logs to S3 or CloudWatch Logs for long-term auditing and compliance.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.