SCS-C02 Security Logging and Monitoring Practice Question
A security engineer needs to detect unauthorized API calls in an AWS account. Which AWS service should be used to record and monitor API activity for auditing?
⚠ Common exam trap
Watch out — candidates often confuse CloudWatch Logs (which stores logs) with CloudTrail (which records API activity), or they assume GuardDuty's threat detection capability includes native API logging, when in fact GuardDuty consumes CloudTrail logs rather than generating them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it is specifically designed to record API activity across AWS services, capturing details such as the identity of the caller, the time of the call, the source IP address, and the request parameters. This audit log is essential for detecting unauthorized API calls, as it provides a complete history of all management and data plane operations for security analysis and compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the native audit service that records every API call and user activity as CloudTrail event history. Each event includes the identity of the caller, source IP, time, request parameters, and response, allowing engineers to detect unauthorized API calls by analyzing management and data events. This event history can be delivered to an S3 bucket and queried with Athena, or streamed to CloudWatch Logs for real-time alerting.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs centralizes log files emitted by AWS services and applications, such as application logs, VPC flow logs, and Lambda execution logs. It does not natively capture AWS API calls; if CloudTrail event data is needed in CloudWatch Logs, you must configure a CloudTrail trail to deliver events there. Therefore, CloudWatch Logs is a destination for the data, not the service that records API activity.
- ✗
AWS Config
Why it's wrong here
AWS Config is a resource compliance and configuration management service that continuously records resource configuration changes and evaluates them against rules. It tracks state transitions and configuration history for resources like EC2 instances, security groups, or S3 buckets, but it does not capture who invoked an API action or what request was made. While it can help detect resource drift, it cannot identify unauthorized API calls.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a managed threat detection service that analyzes thematically derived findings from sources such as DNS logs, VPC Flow Logs, and CloudTrail management events. By consuming CloudTrail events and applying machine learning, GuardDuty can alert on patterns that indicate unauthorized API activity, such as unusual login locations or API calls from known malicious IPs. However, GuardDuty is a downstream analyzer and detector; it is not the service that provides the authoritative audit trail of API calls.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.