Courseiva
Security and Compliance →mediumMultiple Select

SOA-C02 Security and Compliance Practice Question

A company needs to audit all changes to AWS resources. Which THREE AWS services should be used together to achieve this? (Choose three.)

⚠ Common exam trap

SOA-C02 often tests the confusion between auditing (CloudTrail/Config) and security assessment (Inspector) or advisory (Trusted Advisor) services — candidates must map each service to its actual function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail (B) is correct because it records API activity and management events across the account, providing the audit trail of who made which changes to AWS resources. AWS Config (E) is correct because it continuously records resource configuration changes and evaluates them against desired rules, giving configuration history and compliance auditing. Amazon CloudWatch Events (C) is correct because it can detect and route CloudTrail/Config-related events in near real time to targets such as Lambda, SNS, or SQS for alerting and automated response. Amazon Inspector (A) is not correct because it is a vulnerability management service that scans EC2 instances and container images, not a change-auditing service. AWS Trusted Advisor (D) is not correct because it provides best-practice checks and recommendations, not a record of resource changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that performs automated security assessments, scanning for software vulnerabilities and unintended network exposure in workloads. It does not capture or maintain an audit trail of resource configuration modifications; it only evaluates the security state of a resource at the time of a scan. Therefore, it is not suitable for auditing all changes to AWS resources.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the primary service for auditing by recording all API activity across AWS accounts. It captures every management event, including the identity making the call, the source IP, the time, and the request parameters, delivering a complete and verifiable history of who changed what. This immutable log provides the evidence required to audit changes and maintain compliance.

  • ✓

    Amazon CloudWatch Events

    Why this is correct

    Amazon CloudWatch Events (now often referred to as Amazon EventBridge) enables real-time rule-based routing of AWS resource state changes and API call events forwarded by CloudTrail. It can trigger actions such as AWS Lambda functions or SNS notifications when a change is detected, allowing immediate monitoring and response to changes. However, it does not itself retain an immutable audit log; it complements services like CloudTrail by initiating automated audit workflows.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is an advisory service that inspects your AWS environment for best-practice checks in categories like cost optimization, performance, security, and fault tolerance. It provides recommendations for improvement but does not record, store, or report on the history of configuration changes made to resources. Thus, it cannot be used to audit all changes.

  • ✓

    AWS Config

    Why this is correct

    AWS Config is a service that continuously records AWS resource configuration changes and maintains a timeline of each resource's configuration history. It evaluates configurations against desired policies and can generate detailed snapshots and configuration item histories, enabling you to trace exactly what changed and when. This makes it a key service for auditing and compliance monitoring.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.