Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer needs to audit all API calls made in an AWS account for the past 90 days. Which AWS service should the engineer use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail (Option B) is the correct service for auditing all API calls made in an AWS account over the past 90 days. It records API activity and can be configured to store logs for 90 days in the management event history. Option A (Amazon S3 access logs) logs access to S3 objects, not API calls. Option C (AWS Config) tracks resource configuration changes, not API calls. Option D (Amazon CloudWatch Logs) is for monitoring, storing, and accessing log files from various sources, but it is not specifically designed for auditing API calls; CloudTrail is the primary service for that purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon S3 access logs

    Why it's wrong here

    S3 access logs record individual requests made to a specific S3 bucket, such as object-level GETs or PUTs, and are delivered on a best-effort basis. They capture only S3 data plane operations, not the control-plane API calls (e.g., creating a bucket or modifying IAM policies) and nothing from other AWS services. Therefore, they are far too narrow to serve as an organization-wide audit of all API calls.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the authoritative audit service that records every API call made in the account, including the identity of the principal, the source IP address, the time, and the request parameters. By default, it captures management events across all AWS services, and it can be configured to log data events for services like S3 and Lambda. These event logs are delivered to an S3 bucket and can be integrated with CloudWatch Logs for alerting and analysis, making it the correct choice for comprehensive API auditing.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config continuously evaluates and records the configuration state of AWS resources, such as whether an EC2 instance is using a certain AMI or if a security group has a specific rule. It does not log the API calls that initiate those configuration changes, so it cannot answer 'who made this change and when?' directly. Config is a compliance and resource-tracking tool, not an API activity audit trail, making it unsuitable for this requirement.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is a centralized log storage and analysis service that ingests log data from applications, infrastructure, and other AWS services, but it does not natively generate API activity records. While CloudTrail logs can be streamed into CloudWatch Logs for near-real-time monitoring and alerts, the service itself is a destination and query engine, not a source of audit data. Without CloudTrail or another producer feeding it, CloudWatch Logs cannot fulfill the requirement to audit all API calls.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.