SCS-C02 Security Logging and Monitoring Practice Question
A security engineer needs to ensure that all API calls made to AWS are logged and retained for at least 7 years for compliance. Which AWS service should be enabled to meet this requirement?
⚠ Common exam trap
Watch out — candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), but Config does not record the API calls themselves—only the resulting state changes, which may not satisfy compliance requirements for full API audit trails.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records all API calls made to AWS, including the identity of the caller, the time of the call, the source IP address, and the request parameters. CloudTrail logs can be stored in an S3 bucket with lifecycle policies to retain logs for exactly 7 years, meeting the compliance requirement for long-term retention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a machine learning-based threat detection service that consumes CloudTrail management event logs, VPC Flow Logs, and DNS query logs to identify suspicious activity. It does not itself record or store raw API calls; it only analyzes event streams that already exist, so enabling GuardDuty alone cannot ensure all API calls are captured or retained. Its alerts may reference API activity, but the authoritative audit record still depends on CloudTrail.
- ✗
AWS Config
Why it's wrong here
AWS Config tracks configuration state changes and evaluates resources against desired policies, such as whether an S3 bucket is public or a security group allows unrestricted access. When an API call changes a resource, Config may generate a configuration item, but it does not log the full API request, the IAM principal who made it, or the request parameters for every operation. Config also does not capture read-only API calls that do not alter configuration state, so it cannot meet a requirement to ensure all API calls are recorded.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that performs automated security assessments of EC2 instances, container images, and Lambda functions to identify software vulnerabilities and unintended network exposure. It is not an audit or API logging mechanism and produces assessment findings rather than a chronological record of API activity. Consequently, it has no mechanism to capture, retain, or query API call history across the account.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the service designed to record API activity across AWS, capturing the identity of the caller, source IP address, event time, request parameters, and response elements for management events by default. You can create trails that deliver compressed event logs to an Amazon S3 bucket, CloudWatch Logs, or CloudTrail Lake for long-term retention and analysis. For complete coverage, use a multi-region trail with management events enabled and add data events for S3, Lambda, and other services as needed, because CloudTrail is the authoritative source for ensuring all API calls are auditable.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.