SCS-C02 Management and Security Governance Practice Question
A security engineer needs to audit all API calls made in an AWS account for the past 90 days. Which AWS service should the engineer use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail (Option B) is the correct service for auditing all API calls made in an AWS account over the past 90 days. It records API activity and can be configured to store logs for 90 days in the management event history. Option A (Amazon S3 access logs) logs access to S3 objects, not API calls. Option C (AWS Config) tracks resource configuration changes, not API calls. Option D (Amazon CloudWatch Logs) is for monitoring, storing, and accessing log files from various sources, but it is not specifically designed for auditing API calls; CloudTrail is the primary service for that purpose.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon S3 access logs
Why it's wrong here
S3 access logs record individual requests made to a specific S3 bucket, such as object-level GETs or PUTs, and are delivered on a best-effort basis. They capture only S3 data plane operations, not the control-plane API calls (e.g., creating a bucket or modifying IAM policies) and nothing from other AWS services. Therefore, they are far too narrow to serve as an organization-wide audit of all API calls.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the authoritative audit service that records every API call made in the account, including the identity of the principal, the source IP address, the time, and the request parameters. By default, it captures management events across all AWS services, and it can be configured to log data events for services like S3 and Lambda. These event logs are delivered to an S3 bucket and can be integrated with CloudWatch Logs for alerting and analysis, making it the correct choice for comprehensive API auditing.
- ✗
AWS Config
Why it's wrong here
AWS Config continuously evaluates and records the configuration state of AWS resources, such as whether an EC2 instance is using a certain AMI or if a security group has a specific rule. It does not log the API calls that initiate those configuration changes, so it cannot answer 'who made this change and when?' directly. Config is a compliance and resource-tracking tool, not an API activity audit trail, making it unsuitable for this requirement.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a centralized log storage and analysis service that ingests log data from applications, infrastructure, and other AWS services, but it does not natively generate API activity records. While CloudTrail logs can be streamed into CloudWatch Logs for near-real-time monitoring and alerts, the service itself is a destination and query engine, not a source of audit data. Without CloudTrail or another producer feeding it, CloudWatch Logs cannot fulfill the requirement to audit all API calls.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.