Courseiva

SCS-C02 Management and Security Governance Practice Question

A company wants to log all API calls made in their AWS account for auditing. Which AWS service should be enabled to capture these logs?

⚠ Common exam trap

SCS-C02 often tests the difference between CloudTrail (API call auditing) and VPC Flow Logs (network traffic) or S3 access logs (bucket-level requests), so candidates pick a logging service that does not capture account-wide API activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail records API calls made in an AWS account, including the identity, time, source IP, and request details, which is exactly what is needed for auditing. Enabling CloudTrail captures management and, optionally, data events across services. This makes it the correct service for logging all API calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic at the network interface level—source/destination addresses, ports, protocol, and whether packets were accepted or rejected. They provide network-level telemetry for troubleshooting connectivity and analyzing traffic patterns, but they do not include identity, request parameters, or any indication of which IAM user or service made an API call. Consequently, VPC Flow Logs cannot be used to audit API activity.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is a centralized log storage, monitoring, and alerting service that will ingest log streams from sources such as applications, EC2 instances, and other AWS services. However, it is not a native source of AWS API call records; unless you configure a CloudTrail trail to deliver events to CloudWatch Logs, no API activity will appear there. Thus, CloudWatch Logs is purely a destination/aggregator, not the service that captures the API calls.

  • ✗

    Amazon S3 server access logs

    Why it's wrong here

    Amazon S3 server access logs provide detailed records of requests sent to a specific S3 bucket, including object-level operations like PUT, GET, DELETE, and the requester's identity or source IP. These logs are scoped solely to S3 API operations and do not capture calls made to other services such as EC2, IAM, Lambda, or DynamoDB. Therefore, S3 access logs are insufficient for a comprehensive audit of all API calls across the AWS environment.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the purpose-built service that records API activity across your AWS account, capturing management events for the control plane and optionally data events for services like S3. Each event includes the identity of the caller, source IP address, request parameters, response elements, and a timestamp, whether the call came from the console, SDK, or CLI. CloudTrail's event history provides 90 days of visibility by default, and you can create trails to deliver logs to S3 or CloudWatch Logs for long-term auditing and compliance.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.