SCS-C02 Data Protection Practice Question
A security engineer needs to audit all access to a KMS customer managed key. Which AWS service should be used?
⚠ Common exam trap
The trap is confusing configuration auditing (AWS Config) with access auditing (CloudTrail); Config tells you what a resource looks like, CloudTrail tells you who did what to it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail records every API call made to KMS, including Encrypt, Decrypt, GenerateDataKey, CreateKey, and key policy changes, capturing the caller identity, source IP, timestamp, and request parameters. This makes CloudTrail the authoritative service for auditing KMS key usage and access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration and compliance service that records and evaluates resource configuration changes—for example, KMS key policy edits, key rotation status, or alias changes—rather than API calls or access events. It cannot show who invoked a KMS operation or which encryption and decryption requests were made, so it is not a substitute for CloudTrail. AWS Config may detect configuration drift, but it cannot serve as the audit trail for KMS access.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture IP traffic metadata at the network interface level—such as source and destination addresses, ports, protocol, and accepted/rejected packets—but they operate at Layers 3 and 4. They cannot inspect the contents of TLS-encrypted KMS API requests, nor can they identify the IAM principal, the key ID, or the specific KMS operation performed. Therefore, VPC Flow Logs cannot provide an audit trail of KMS access.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a centralized service for storing, monitoring, and alerting on log data; it does not itself generate KMS API audit records. CloudWatch Logs can only contain KMS audit events if a CloudTrail trail is explicitly configured to deliver its event log to a CloudWatch Logs log group, making CloudWatch a downstream destination rather than the audit source. Depending on CloudWatch Logs alone provides no record of who called KMS operations, so it is not the correct service for this requirement.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail records all KMS API requests as audit events, including both management-plane actions (such as CreateKey, EnableKeyRotation, and DescribeCustomKeyStores) and data-plane operations like Encrypt, Decrypt, and GenerateDataKey. Each CloudTrail event captures the caller's IAM identity, source IP address, key ID, request parameters, and timestamp, and can be delivered to Amazon S3 or CloudWatch Logs for long-term retention and analysis. CloudTrail is therefore the authoritative service for auditing all access to a KMS custom key store or the keys associated with it.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.