A security team needs to detect unauthorized API calls made from a compromised IAM user. Which AWS service should be used to monitor and alert on specific API activities?
AWS CloudTrail is the correct choice because it is the native AWS service that records API activity in your account, capturing who made the call, from which source IP, what action was invoked, and when it occurred. For unauthorized API call detection, you can enable CloudTrail across all regions, turn on data events for sensitive services like S3 or Lambda, and use CloudTrail Lake or integration with Amazon EventBridge to trigger real-time alerts on specific unauthorized actions. Unlike configuration state or network flow data, CloudTrail delivers a complete audit trail of every management and data-plane API call.
Why this answer
AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including those from IAM users, and delivers event history for auditing. By enabling CloudTrail trails with management event logging and configuring Amazon CloudWatch alarms or EventBridge rules on specific API actions (e.g., `iam:CreateUser`, `ec2:AuthorizeSecurityGroupIngress`), the security team can detect and alert on unauthorized API activities from a compromised IAM user.
Exam trap
The trap here is that candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which logs API calls), or they assume GuardDuty's threat detection covers all API-level monitoring, but GuardDuty does not provide per-API-call logging or allow custom alerting on specific actions like `iam:CreateAccessKey`.
How to eliminate wrong answers
Option B (AWS Config) is wrong because it evaluates resource configurations against desired policies and tracks configuration changes, not API call activities; it cannot log or alert on specific API actions like `iam:CreateAccessKey`. Option C (Amazon GuardDuty) is wrong because it uses threat intelligence and anomaly detection to identify malicious behavior (e.g., unusual network traffic, compromised credentials) but does not provide granular, per-API-call logging or allow alerting on specific API actions; it focuses on broader threat detection rather than auditing individual API calls. Option D (VPC Flow Logs) is wrong because it captures metadata about IP traffic within VPCs (e.g., source/destination IP, ports, protocol) and has no visibility into AWS API calls made by IAM users; it operates at the network layer, not the control plane.