Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A security engineer needs to audit all access to a KMS customer managed key. Which AWS service should be used?

⚠ Common exam trap

The trap is confusing configuration auditing (AWS Config) with access auditing (CloudTrail); Config tells you what a resource looks like, CloudTrail tells you who did what to it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail records every API call made to KMS, including Encrypt, Decrypt, GenerateDataKey, CreateKey, and key policy changes, capturing the caller identity, source IP, timestamp, and request parameters. This makes CloudTrail the authoritative service for auditing KMS key usage and access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a configuration and compliance service that records and evaluates resource configuration changes—for example, KMS key policy edits, key rotation status, or alias changes—rather than API calls or access events. It cannot show who invoked a KMS operation or which encryption and decryption requests were made, so it is not a substitute for CloudTrail. AWS Config may detect configuration drift, but it cannot serve as the audit trail for KMS access.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata at the network interface level—such as source and destination addresses, ports, protocol, and accepted/rejected packets—but they operate at Layers 3 and 4. They cannot inspect the contents of TLS-encrypted KMS API requests, nor can they identify the IAM principal, the key ID, or the specific KMS operation performed. Therefore, VPC Flow Logs cannot provide an audit trail of KMS access.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is a centralized service for storing, monitoring, and alerting on log data; it does not itself generate KMS API audit records. CloudWatch Logs can only contain KMS audit events if a CloudTrail trail is explicitly configured to deliver its event log to a CloudWatch Logs log group, making CloudWatch a downstream destination rather than the audit source. Depending on CloudWatch Logs alone provides no record of who called KMS operations, so it is not the correct service for this requirement.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail records all KMS API requests as audit events, including both management-plane actions (such as CreateKey, EnableKeyRotation, and DescribeCustomKeyStores) and data-plane operations like Encrypt, Decrypt, and GenerateDataKey. Each CloudTrail event captures the caller's IAM identity, source IP address, key ID, request parameters, and timestamp, and can be delivered to Amazon S3 or CloudWatch Logs for long-term retention and analysis. CloudTrail is therefore the authoritative service for auditing all access to a KMS custom key store or the keys associated with it.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.