Courseiva
Security and Compliance →easyMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company requires that all AWS account activity be recorded and the logs be stored in a centralized S3 bucket for analysis. Which two AWS services should be used together to meet this requirement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail and Amazon S3

AWS CloudTrail and Amazon S3. CloudTrail records all AWS account activity as API call events, and it can be configured with a trail that delivers those event logs to a centralized S3 bucket for storage and later analysis. The other options do not fit: GuardDuty is a threat-detection service that generates findings rather than recording all account activity, AWS Config tracks resource configuration changes and compliance rather than full API activity, Amazon Inspector assesses vulnerabilities on workloads, and VPC Flow Logs capture IP traffic metadata for network interfaces, not AWS account API activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty and Amazon S3

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes findings from various sources like DNS query logs, VPC Flow Logs, and CloudTrail management events, but it does not record raw AWS account activity. It consumes existing logs to identify malicious behavior, not to create an immutable audit trail of all actions. Storing GuardDuty findings in S3 would not capture every API call or management action, so it fails to meet the requirement.

  • ✓

    AWS CloudTrail and Amazon S3

    Why this is correct

    AWS CloudTrail is the correct service for recording all AWS account activity. It captures every API call made in the account, including the identity of the caller, the time of the call, the source IP address, and the requested action, delivering these events as log files. These logs can be delivered to an Amazon S3 bucket for long-term, tamper-evident storage, which directly satisfies the compliance and auditing requirement.

  • ✗

    AWS Config and Amazon S3

    Why it's wrong here

    AWS Config continuously records and evaluates resource configuration changes against desired policies, providing a configuration history and timeline of resource states. However, it does not log the full set of API actions, the identity of the principal making the call, or the request parameters; it only tracks the resulting state of resources after changes occur. Therefore, it is insufficient for recording all account activity as required.

  • ✗

    Amazon Inspector and Amazon S3

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, producing assessment reports. It does not generate logs of AWS account activity, and its reports delivered to S3 do not provide an audit trail of API calls or management events. Inspector is specialized for security assessment, not for capturing a record of every action taken in the account.

  • ✗

    VPC Flow Logs and Amazon S3

    Why it's wrong here

    VPC Flow Logs capture information about IP traffic going to and from network interfaces in a VPC, such as source and destination addresses, ports, and protocol. They do not log AWS API actions or account-level management activity, so they cannot fulfill the requirement to record all account activity. Storing flow logs in S3 preserves only network metadata, not an audit trail of API calls or resource changes.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SysOps administrator needs to audit all IAM user activity in the AWS account for the last 90 days. Which AWS service should be used?

medium
  • A.AWS Config
  • B.AWS Trusted Advisor
  • ✓ C.AWS CloudTrail
  • D.Amazon GuardDuty

Why C: AWS CloudTrail is the correct service because it records all API calls made by IAM users, including console sign-in events, CLI commands, and SDK actions, and retains these logs for up to 90 days by default in the event history. This allows the SysOps administrator to audit all IAM user activity over the last 90 days without additional configuration.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.