Courseiva
Security and Compliance →mediumMultiple Select

SOA-C02 Security and Compliance Practice Question

A company wants to audit all API calls made in their AWS account for compliance. Which THREE AWS services can be used together to capture and store these logs? (Choose three.)

⚠ Common exam trap

SOA-C02 often tests the confusion between CloudTrail (captures API activity) and AWS Config (records resource configuration state) — candidates pick Config thinking it logs API calls, but Config tracks configuration drift, not API events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Logs

AWS CloudTrail (B) is the service that records API activity in an AWS account, capturing management and data events as audit trails, which is exactly what is needed to audit all API calls. Amazon CloudWatch Logs (A) is used to receive and store those CloudTrail event logs via a trail's CloudWatch Logs integration, enabling centralized monitoring and retention of the API call records. Amazon S3 (D) is the destination where CloudTrail delivers the log files for durable, long-term storage and later compliance analysis. AWS Config (C) evaluates resource configurations and compliance against rules rather than capturing API call logs, and Amazon GuardDuty (E) is a threat-detection service that analyzes findings from sources like CloudTrail but does not itself capture and store the raw API call logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    Amazon CloudWatch Logs is correct because it can be the destination for a CloudTrail trail: you can configure CloudTrail to deliver all API call events to a CloudWatch Logs log group. From there, you can store the logs, apply metric filters for real-time monitoring, and retain them for analysis or alerting. This integration makes CloudWatch Logs a valid place to audit and act on API activity, even though CloudTrail itself is the original recorder.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the core audit service in AWS and is correct because it natively records every supported API call made in your account, whether from the console, CLI, SDK, or other services. Each event includes the identity of the caller, the time, the source IP address, the request parameters, and the response elements. This makes CloudTrail the authoritative source for tracing who did what and when across your entire AWS environment.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is incorrect for auditing API calls because it is designed to record resource configuration changes and timestamps, such as when a security group rule changed or an EBS volume was attached, and to evaluate these configurations against compliance rules. It does not capture the callers, the API actions, or the request details that an audit trail requires. While Config can show the result of some changes, it is not an API-level activity log.

  • ✓

    Amazon S3

    Why this is correct

    Amazon S3 is correct because it is the standard durable storage destination for CloudTrail logs. You can deliver log files to an S3 bucket, where they can be retained for long-term compliance, encrypted with SSE-KMS, and made immutable using S3 Object Lock. By running services like Athena or Amazon Macie on the bucket, you can also query and analyze the API-call history, making S3 a practical and scalable audit repository.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is incorrect because it is a threat detection service that continuously monitors for malicious or unauthorized behavior using anomaly detection, threat intelligence feeds, and machine learning. It generates security findings when it detects suspicious activity such as compromised credentials or unusual network patterns, but it does not produce a comprehensive, chronological record of all API calls. GuardDuty is an alerting and protection layer, not an audit trail service.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.