Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to ensure that all API calls made to AWS are logged and retained for at least 7 years for compliance. Which AWS service should be enabled to meet this requirement?

⚠ Common exam trap

Watch out — candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), but Config does not record the API calls themselves—only the resulting state changes, which may not satisfy compliance requirements for full API audit trails.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records all API calls made to AWS, including the identity of the caller, the time of the call, the source IP address, and the request parameters. CloudTrail logs can be stored in an S3 bucket with lifecycle policies to retain logs for exactly 7 years, meeting the compliance requirement for long-term retention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a machine learning-based threat detection service that consumes CloudTrail management event logs, VPC Flow Logs, and DNS query logs to identify suspicious activity. It does not itself record or store raw API calls; it only analyzes event streams that already exist, so enabling GuardDuty alone cannot ensure all API calls are captured or retained. Its alerts may reference API activity, but the authoritative audit record still depends on CloudTrail.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config tracks configuration state changes and evaluates resources against desired policies, such as whether an S3 bucket is public or a security group allows unrestricted access. When an API call changes a resource, Config may generate a configuration item, but it does not log the full API request, the IAM principal who made it, or the request parameters for every operation. Config also does not capture read-only API calls that do not alter configuration state, so it cannot meet a requirement to ensure all API calls are recorded.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that performs automated security assessments of EC2 instances, container images, and Lambda functions to identify software vulnerabilities and unintended network exposure. It is not an audit or API logging mechanism and produces assessment findings rather than a chronological record of API activity. Consequently, it has no mechanism to capture, retain, or query API call history across the account.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the service designed to record API activity across AWS, capturing the identity of the caller, source IP address, event time, request parameters, and response elements for management events by default. You can create trails that deliver compressed event logs to an Amazon S3 bucket, CloudWatch Logs, or CloudTrail Lake for long-term retention and analysis. For complete coverage, use a multi-region trail with management events enabled and add data events for S3, Lambda, and other services as needed, because CloudTrail is the authoritative source for ensuring all API calls are auditable.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.