SCS-C02 Management and Security Governance Practice Question
A security team needs to audit all changes to IAM policies in their AWS account. Which AWS service should they use to record policy changes?
⚠ Common exam trap
Candidates often confuse AWS Config (which tracks resource configuration state) with CloudTrail (which tracks API call history), leading them to choose AWS Config because it can detect drift, but it does not provide the detailed audit trail of who made the change and when.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records all API calls made in the AWS account, including IAM policy changes (e.g., CreatePolicy, PutRolePolicy, AttachUserPolicy). These events are captured as CloudTrail log entries, providing a complete audit trail of who made the change, when, and from which source IP. This directly meets the requirement to audit all changes to IAM policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is an automated vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not an audit trail for API activity. It has no capability to record or log IAM policy modifications, because it operates on EC2 instances and container images rather than on control-plane operations. Relying on Inspector for this audit requirement would provide no relevant evidence of who changed a policy or when.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the correct service because it provides a continuous, immutable audit log of every API call made in your AWS account, including the IAM actions that modify policies such as PutRolePolicy, AttachUserPolicy, and DeletePolicy. Each event captures the identity of the caller, the source IP, the time, and the request parameters, making it the definitive source for security audits of IAM changes. CloudTrail's event history is viewable for 90 days, and you can extend retention with a trail that delivers events to an S3 bucket or CloudWatch Logs for long-term compliance.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior using anomaly detection, threat intelligence, and machine learning. While it can alert you to suspicious API activity or compromised credentials after the fact, it does not provide a complete, structured history of every IAM policy change required for auditing. GuardDuty's findings are derived from CloudTrail events and other sources, so it complements rather than replaces CloudTrail for change audit purposes.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration tracking service that records resource configuration changes and evaluates them against desired policies, so it would capture the fact that an IAM policy resource changed state. However, AWS Config is not the primary audit trail because it focuses on the resulting configuration state and compliance rules, not on the full API request/response details, caller identity, and request parameters that an audit of 'all changes to IAM policies' demands. Config even depends on CloudTrail to record configuration history for resources, making CloudTrail the authoritative service for this audit requirement.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company needs to audit all changes to IAM policies in their AWS account for compliance. Which AWS service should be enabled to record the API calls that modify IAM policies?
easy- A.Amazon CloudWatch Logs
- B.AWS Config
- ✓ C.AWS CloudTrail
- D.VPC Flow Logs
Why C: AWS CloudTrail records API activity in an AWS account, including all calls that modify IAM policies such as CreatePolicy, PutRolePolicy, AttachRolePolicy, and DeletePolicy. Enabling CloudTrail (which is on by default for management events) provides the audit trail of who made the change, when, and from where. This is the correct service for auditing IAM policy modifications.
Variation 2. A company needs to audit all changes to IAM policies in its AWS account. Which AWS service should be used to record the change history of IAM policies?
medium- A.Amazon CloudWatch Logs
- B.Amazon GuardDuty
- ✓ C.AWS CloudTrail
- D.AWS Config
Why C: AWS CloudTrail is the service that records API activity in an AWS account, including all changes to IAM policies. When an IAM policy is created, modified, or deleted, CloudTrail logs the event with details such as the identity of the caller, the time of the API call, the source IP address, and the request parameters. This makes CloudTrail the authoritative source for auditing IAM policy changes.
Variation 3. A company needs to audit all changes to IAM policies in their AWS account. Which AWS service should they use to record these changes?
easy- A.Amazon S3
- B.Amazon CloudWatch Logs
- C.AWS Config
- ✓ D.AWS CloudTrail
Why D: AWS CloudTrail records API activity in an AWS account, including all changes to IAM policies (CreatePolicy, PutRolePolicy, AttachRolePolicy, etc.). CloudTrail captures the identity of the caller, the time, the source IP, and the request parameters, making it the authoritative service for auditing IAM policy changes. It is enabled by default for management events and can be configured for multi-region and organization-wide trails.
Variation 4. A security team wants to audit all changes to IAM policies in the AWS account. Which AWS service should be used to track these changes?
easy- A.AWS Config
- B.AWS Trusted Advisor
- ✓ C.AWS CloudTrail
- D.AWS CloudWatch Logs
Why C: AWS CloudTrail records API activity in the account, including all IAM policy changes (CreatePolicy, PutRolePolicy, AttachPolicy, etc.), and delivers these events to an S3 bucket and optionally CloudWatch Logs. It is the authoritative service for auditing who changed what and when across AWS APIs. For IAM policy change auditing, CloudTrail is the correct and standard answer.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.