Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer needs to ensure that all API calls made to AWS services are logged for auditing. Which AWS service should be used?

⚠ Common exam trap

Many candidates confuse AWS Config (which tracks configuration changes) with CloudTrail (which logs API calls), or they mistakenly think VPC Flow Logs or CloudWatch Logs are the primary services for API auditing, when in fact CloudTrail is the dedicated service for recording all AWS API activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records all API calls made to AWS services, capturing details such as the identity of the caller, the time of the call, the source IP address, request parameters, and response elements. This provides a complete audit trail of user activity and API usage, which is essential for security auditing and compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a service that records resource configuration changes and evaluates them against compliance rules, but it does not capture the API calls that initiated those changes. While Config can show a configuration history and timeline for a resource, it lacks the request-level details such as the calling IAM identity, source IP address, and request parameters. Therefore, relying on Config would not satisfy the requirement to ensure all API calls are recorded.

  • ✗

    Amazon VPC Flow Logs

    Why it's wrong here

    Amazon VPC Flow Logs capture metadata about IP traffic to and from network interfaces, such as source/destination addresses, ports, protocols, and packet counts. They operate at the network layer and do not log application-level API operations, including AWS management/control plane calls like IAM AssumeRole or Amazon S3 PUT requests made via an SDK or console. Flow Logs are useful for traffic analysis but not for auditing API activity across AWS services.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the appropriate service for capturing API activity across AWS. It records management events by default, including actions performed through the AWS Management Console, SDKs, CLI, and other services, and can be configured to log data events for services like Amazon S3 and Lambda. Each CloudTrail event provides the identity, timestamp, source IP, request parameters, and response elements, making it the definitive source for API call auditing.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is a centralized service for storing, monitoring, and querying log data, but it does not natively capture AWS API calls on its own. It can serve as a delivery destination for CloudTrail events, enabling long-term retention and metric filters, but those events must first be generated by CloudTrail. Without CloudTrail, CloudWatch Logs would have no API activity to store.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.