A security engineer needs to ensure that all API calls in an AWS account are logged for incident response. Which AWS service should be enabled?
AWS CloudTrail is the only service that directly records AWS API activity as first-class audit log events. When enabled, it captures the identity of the caller (IAM user or role), the source IP address, the requested action, request parameters, and the response returned by the service, for both management events and (when configured) data events. These logs can be delivered to Amazon S3 and CloudWatch Logs, and the trail can be multi-region and organization-wide, making CloudTrail the authoritative record of every API call for incident response and governance. Unlike anomaly-detection services such as GuardDuty, CloudTrail does not infer or analyze behavior—it simply logs each call exactly as it occurred.
Why this answer
AWS CloudTrail is the correct service because it records all API calls made in an AWS account, including the identity of the caller, the time of the call, the source IP address, and the request parameters. This logging is essential for incident response to reconstruct events and identify unauthorized or malicious activity.
Exam trap
The trap here is that candidates confuse AWS Config with CloudTrail because both deal with 'logging' and 'compliance,' but Config tracks resource state changes over time, not the API calls that caused those changes.
How to eliminate wrong answers
Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (like CloudTrail, VPC Flow Logs, and DNS logs) for malicious activity, but it does not itself generate or store API call logs. Option B is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) at the elastic network interface level, not API calls to AWS services. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance rules, but it does not log API calls; it relies on CloudTrail for API history.