A security team needs to audit all changes to IAM resources in their AWS account. Which AWS service should they use?
AWS CloudTrail records API activity across the account, including every IAM create, update, and delete operation, with the identity, timestamp, and source IP. This provides the complete audit trail the security team needs to track all IAM resource changes.
Why this answer
AWS CloudTrail records API activity across the AWS account, including all IAM resource changes such as CreateUser, AttachPolicy, DeleteRole, and UpdateAssumeRolePolicy. It captures the identity of the caller, the time, the source IP, and the request parameters, making it the authoritative audit trail for IAM modifications. CloudTrail event history provides 90 days of management events by default, and trails can deliver logs to S3 for long-term retention.
Exam trap
SCS-C02 often tests the distinction between CloudTrail (API activity audit), AWS Config (resource configuration history and compliance), and VPC Flow Logs (network traffic metadata), so candidates must match the service to the specific audit requirement — IAM changes require CloudTrail.
How to eliminate wrong answers
Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, accept/reject) at the ENI, subnet, or VPC level — they do not record IAM API calls or resource changes. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance against rules, but it does not provide the full API-level audit trail of who made each IAM change; it shows the resulting configuration state, not the API call details. Option D is wrong because Amazon CloudWatch Logs stores application and service logs, but IAM API activity is not automatically published there — CloudTrail is the service that captures IAM API calls, and CloudWatch Logs can receive CloudTrail logs only if explicitly configured.