SOA-C02 Security and Compliance Practice Question
A company requires that all AWS account activity be recorded and the logs be stored in a centralized S3 bucket for analysis. Which two AWS services should be used together to meet this requirement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail and Amazon S3
AWS CloudTrail and Amazon S3. CloudTrail records all AWS account activity as API call events, and it can be configured with a trail that delivers those event logs to a centralized S3 bucket for storage and later analysis. The other options do not fit: GuardDuty is a threat-detection service that generates findings rather than recording all account activity, AWS Config tracks resource configuration changes and compliance rather than full API activity, Amazon Inspector assesses vulnerabilities on workloads, and VPC Flow Logs capture IP traffic metadata for network interfaces, not AWS account API activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty and Amazon S3
Why it's wrong here
Amazon GuardDuty is a threat detection service that analyzes findings from various sources like DNS query logs, VPC Flow Logs, and CloudTrail management events, but it does not record raw AWS account activity. It consumes existing logs to identify malicious behavior, not to create an immutable audit trail of all actions. Storing GuardDuty findings in S3 would not capture every API call or management action, so it fails to meet the requirement.
- ✓
AWS CloudTrail and Amazon S3
Why this is correct
AWS CloudTrail is the correct service for recording all AWS account activity. It captures every API call made in the account, including the identity of the caller, the time of the call, the source IP address, and the requested action, delivering these events as log files. These logs can be delivered to an Amazon S3 bucket for long-term, tamper-evident storage, which directly satisfies the compliance and auditing requirement.
- ✗
AWS Config and Amazon S3
Why it's wrong here
AWS Config continuously records and evaluates resource configuration changes against desired policies, providing a configuration history and timeline of resource states. However, it does not log the full set of API actions, the identity of the principal making the call, or the request parameters; it only tracks the resulting state of resources after changes occur. Therefore, it is insufficient for recording all account activity as required.
- ✗
Amazon Inspector and Amazon S3
Why it's wrong here
Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, producing assessment reports. It does not generate logs of AWS account activity, and its reports delivered to S3 do not provide an audit trail of API calls or management events. Inspector is specialized for security assessment, not for capturing a record of every action taken in the account.
- ✗
VPC Flow Logs and Amazon S3
Why it's wrong here
VPC Flow Logs capture information about IP traffic going to and from network interfaces in a VPC, such as source and destination addresses, ports, and protocol. They do not log AWS API actions or account-level management activity, so they cannot fulfill the requirement to record all account activity. Storing flow logs in S3 preserves only network metadata, not an audit trail of API calls or resource changes.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A SysOps administrator needs to audit all IAM user activity in the AWS account for the last 90 days. Which AWS service should be used?
medium- A.AWS Config
- B.AWS Trusted Advisor
- ✓ C.AWS CloudTrail
- D.Amazon GuardDuty
Why C: AWS CloudTrail is the correct service because it records all API calls made by IAM users, including console sign-in events, CLI commands, and SDK actions, and retains these logs for up to 90 days by default in the event history. This allows the SysOps administrator to audit all IAM user activity over the last 90 days without additional configuration.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.