SOA-C02 Security and Compliance Practice Question
A company wants to audit all API calls made in their AWS account for compliance. Which THREE AWS services can be used together to capture and store these logs? (Choose three.)
⚠ Common exam trap
SOA-C02 often tests the confusion between CloudTrail (captures API activity) and AWS Config (records resource configuration state) — candidates pick Config thinking it logs API calls, but Config tracks configuration drift, not API events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Logs
AWS CloudTrail (B) is the service that records API activity in an AWS account, capturing management and data events as audit trails, which is exactly what is needed to audit all API calls. Amazon CloudWatch Logs (A) is used to receive and store those CloudTrail event logs via a trail's CloudWatch Logs integration, enabling centralized monitoring and retention of the API call records. Amazon S3 (D) is the destination where CloudTrail delivers the log files for durable, long-term storage and later compliance analysis. AWS Config (C) evaluates resource configurations and compliance against rules rather than capturing API call logs, and Amazon GuardDuty (E) is a threat-detection service that analyzes findings from sources like CloudTrail but does not itself capture and store the raw API call logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon CloudWatch Logs
Why this is correct
Amazon CloudWatch Logs is correct because it can be the destination for a CloudTrail trail: you can configure CloudTrail to deliver all API call events to a CloudWatch Logs log group. From there, you can store the logs, apply metric filters for real-time monitoring, and retain them for analysis or alerting. This integration makes CloudWatch Logs a valid place to audit and act on API activity, even though CloudTrail itself is the original recorder.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the core audit service in AWS and is correct because it natively records every supported API call made in your account, whether from the console, CLI, SDK, or other services. Each event includes the identity of the caller, the time, the source IP address, the request parameters, and the response elements. This makes CloudTrail the authoritative source for tracing who did what and when across your entire AWS environment.
- ✗
AWS Config
Why it's wrong here
AWS Config is incorrect for auditing API calls because it is designed to record resource configuration changes and timestamps, such as when a security group rule changed or an EBS volume was attached, and to evaluate these configurations against compliance rules. It does not capture the callers, the API actions, or the request details that an audit trail requires. While Config can show the result of some changes, it is not an API-level activity log.
- ✓
Amazon S3
Why this is correct
Amazon S3 is correct because it is the standard durable storage destination for CloudTrail logs. You can deliver log files to an S3 bucket, where they can be retained for long-term compliance, encrypted with SSE-KMS, and made immutable using S3 Object Lock. By running services like Athena or Amazon Macie on the bucket, you can also query and analyze the API-call history, making S3 a practical and scalable audit repository.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is incorrect because it is a threat detection service that continuously monitors for malicious or unauthorized behavior using anomaly detection, threat intelligence feeds, and machine learning. It generates security findings when it detects suspicious activity such as compromised credentials or unusual network patterns, but it does not produce a comprehensive, chronological record of all API calls. GuardDuty is an alerting and protection layer, not an audit trail service.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.