Courseiva
Security and Compliance →easyMultiple Select

SOA-C02 Security and Compliance Practice Question

A company wants to audit all API calls made in their AWS account for security analysis. They need to record both management events and data events. Which THREE steps should be taken to set up comprehensive logging? (Choose THREE.)

⚠ Common exam trap

SOA-C02 often tests the distinction between CloudTrail (API activity) and VPC Flow Logs (network traffic) — candidates pick Flow Logs thinking 'all activity' includes API calls, but Flow Logs cannot see IAM identities or API actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail to record data events for S3 and Lambda.

Option A is correct because CloudTrail data events are not logged by default; you must explicitly enable them for resources like S3 objects and Lambda invocations to capture those API-level operations. Option B is correct because management events (control-plane operations such as CreateBucket or RunInstances) are the core of CloudTrail auditing and must be enabled on the trail to record API activity across the account. Option E is correct because a CloudTrail trail must deliver its log files to an Amazon S3 bucket, which is the required destination for storing and later analyzing the audit logs. Option C is not correct because VPC Flow Logs capture IP traffic metadata for network interfaces, not API call details, so they do not satisfy the API auditing requirement. Option D is not correct because sending logs to CloudWatch Logs is an optional enhancement for monitoring and alerting, not a required step for setting up comprehensive CloudTrail logging of management and data events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable AWS CloudTrail to record data events for S3 and Lambda.

    Why this is correct

    Data events capture object-level API operations for S3, such as GetObject, PutObject, and DeleteObject, as well as Lambda function invocations. Unlike management events, data events are not enabled by default; you must explicitly configure the trail to include them, which is essential for auditing access to sensitive content and detecting suspicious data read/write patterns. Without this explicit enablement, the audit will miss critical resource-level activity that management events do not cover.

  • ✓

    Enable AWS CloudTrail to record management events.

    Why this is correct

    Management events record control-plane operations that create, modify, or delete AWS resources, such as launching an EC2 instance, altering IAM policies, or deleting an S3 bucket. These events are logged by default whenever you activate CloudTrail, so no additional configuration is needed to capture them; however, you should confirm the trail is active and covers all regions to ensure complete accountability. Management events provide a high-level audit of administrative actions across the entire account, complementing the resource-specific detail offered by data events.

  • ✗

    Enable VPC Flow Logs to capture API call metadata.

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic to and from network interfaces, not API calls. The requirement is to record management and data events from AWS API operations, which CloudTrail handles by logging API activity at the account level. VPC Flow Logs are tempting because they provide network-level visibility, but they lack the ability to log the specific API request parameters, identity, or resource ARNs needed for security analysis of API calls. They would be correct for diagnosing network connectivity issues or inspecting traffic patterns.

  • ✗

    Send the log files to Amazon CloudWatch Logs for real-time analysis.

    Why it's wrong here

    Sending CloudTrail logs to Amazon CloudWatch Logs is an optional downstream integration that enables real-time monitoring, metric filters, and alarms based on API activity. It does not influence whether CloudTrail records events; CloudTrail logs independently of any log destinations, so omitting this step still leaves recording fully intact. While useful for immediate alerting and operational response, this is not a required step for auditing because the core recording mechanism is CloudTrail itself, not the delivery channel.

  • ✓

    Configure the trail to deliver log files to an S3 bucket.

    Why this is correct

    Configuring the trail to deliver log files to an S3 bucket is the standard and necessary method for durable, long-term storage of CloudTrail logs, ensuring that audit records persist for compliance and forensic analysis. When you create a trail, you specify an S3 bucket where logs are stored as gzipped JSON objects; you can also apply encryption, versioning, and bucket policies to protect them. Without an S3 destination, there would be no persistent log repository, making it impossible to satisfy regulatory or historical audit requirements.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.