A security engineer is setting up monitoring for AWS API calls. Which TWO AWS services can be used to capture and analyze API activity?
Amazon CloudWatch Logs is the monitoring and analysis layer that ingests CloudTrail events when a trail is configured to deliver to a log group. It enables real-time and historical inspection of API calls through metric filters, which can trigger CloudWatch Alarms based on specific API activity, and CloudWatch Logs Insights for ad-hoc querying. This makes it the correct service for actively monitoring and alerting on AWS API calls, rather than merely recording them.
Why this answer
Amazon CloudWatch Logs can capture and analyze API activity by ingesting log data from various AWS services, including AWS CloudTrail. You can configure CloudWatch Logs to monitor API calls in real time, set up metric filters to detect specific patterns, and trigger alarms based on API activity. This makes it a valid service for capturing and analyzing API calls, especially when combined with CloudTrail for detailed event records.
Exam trap
The trap here is that candidates often confuse AWS Config (which records resource configuration changes) with CloudTrail (which records API calls), or they think Amazon GuardDuty directly captures API logs, when in fact it only analyzes logs from other services like CloudTrail.