SOA-C02 Security and Compliance Practice Question
A company needs to audit all changes to AWS resources. Which THREE AWS services should be used together to achieve this? (Choose three.)
⚠ Common exam trap
SOA-C02 often tests the confusion between auditing (CloudTrail/Config) and security assessment (Inspector) or advisory (Trusted Advisor) services — candidates must map each service to its actual function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail (B) is correct because it records API activity and management events across the account, providing the audit trail of who made which changes to AWS resources. AWS Config (E) is correct because it continuously records resource configuration changes and evaluates them against desired rules, giving configuration history and compliance auditing. Amazon CloudWatch Events (C) is correct because it can detect and route CloudTrail/Config-related events in near real time to targets such as Lambda, SNS, or SQS for alerting and automated response. Amazon Inspector (A) is not correct because it is a vulnerability management service that scans EC2 instances and container images, not a change-auditing service. AWS Trusted Advisor (D) is not correct because it provides best-practice checks and recommendations, not a record of resource changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that performs automated security assessments, scanning for software vulnerabilities and unintended network exposure in workloads. It does not capture or maintain an audit trail of resource configuration modifications; it only evaluates the security state of a resource at the time of a scan. Therefore, it is not suitable for auditing all changes to AWS resources.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the primary service for auditing by recording all API activity across AWS accounts. It captures every management event, including the identity making the call, the source IP, the time, and the request parameters, delivering a complete and verifiable history of who changed what. This immutable log provides the evidence required to audit changes and maintain compliance.
- ✓
Amazon CloudWatch Events
Why this is correct
Amazon CloudWatch Events (now often referred to as Amazon EventBridge) enables real-time rule-based routing of AWS resource state changes and API call events forwarded by CloudTrail. It can trigger actions such as AWS Lambda functions or SNS notifications when a change is detected, allowing immediate monitoring and response to changes. However, it does not itself retain an immutable audit log; it complements services like CloudTrail by initiating automated audit workflows.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor is an advisory service that inspects your AWS environment for best-practice checks in categories like cost optimization, performance, security, and fault tolerance. It provides recommendations for improvement but does not record, store, or report on the history of configuration changes made to resources. Thus, it cannot be used to audit all changes.
- ✓
AWS Config
Why this is correct
AWS Config is a service that continuously records AWS resource configuration changes and maintains a timeline of each resource's configuration history. It evaluates configurations against desired policies and can generate detailed snapshots and configuration item histories, enabling you to trace exactly what changed and when. This makes it a key service for auditing and compliance monitoring.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.