SOA-C02 Security and Compliance Practice Question
A company wants to audit all API calls made in their AWS account for security analysis. They need to record both management events and data events. Which THREE steps should be taken to set up comprehensive logging? (Choose THREE.)
⚠ Common exam trap
SOA-C02 often tests the distinction between CloudTrail (API activity) and VPC Flow Logs (network traffic) — candidates pick Flow Logs thinking 'all activity' includes API calls, but Flow Logs cannot see IAM identities or API actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS CloudTrail to record data events for S3 and Lambda.
Option A is correct because CloudTrail data events are not logged by default; you must explicitly enable them for resources like S3 objects and Lambda invocations to capture those API-level operations. Option B is correct because management events (control-plane operations such as CreateBucket or RunInstances) are the core of CloudTrail auditing and must be enabled on the trail to record API activity across the account. Option E is correct because a CloudTrail trail must deliver its log files to an Amazon S3 bucket, which is the required destination for storing and later analyzing the audit logs. Option C is not correct because VPC Flow Logs capture IP traffic metadata for network interfaces, not API call details, so they do not satisfy the API auditing requirement. Option D is not correct because sending logs to CloudWatch Logs is an optional enhancement for monitoring and alerting, not a required step for setting up comprehensive CloudTrail logging of management and data events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable AWS CloudTrail to record data events for S3 and Lambda.
Why this is correct
Data events capture object-level API operations for S3, such as GetObject, PutObject, and DeleteObject, as well as Lambda function invocations. Unlike management events, data events are not enabled by default; you must explicitly configure the trail to include them, which is essential for auditing access to sensitive content and detecting suspicious data read/write patterns. Without this explicit enablement, the audit will miss critical resource-level activity that management events do not cover.
- ✓
Enable AWS CloudTrail to record management events.
Why this is correct
Management events record control-plane operations that create, modify, or delete AWS resources, such as launching an EC2 instance, altering IAM policies, or deleting an S3 bucket. These events are logged by default whenever you activate CloudTrail, so no additional configuration is needed to capture them; however, you should confirm the trail is active and covers all regions to ensure complete accountability. Management events provide a high-level audit of administrative actions across the entire account, complementing the resource-specific detail offered by data events.
- ✗
Enable VPC Flow Logs to capture API call metadata.
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic to and from network interfaces, not API calls. The requirement is to record management and data events from AWS API operations, which CloudTrail handles by logging API activity at the account level. VPC Flow Logs are tempting because they provide network-level visibility, but they lack the ability to log the specific API request parameters, identity, or resource ARNs needed for security analysis of API calls. They would be correct for diagnosing network connectivity issues or inspecting traffic patterns.
- ✗
Send the log files to Amazon CloudWatch Logs for real-time analysis.
Why it's wrong here
Sending CloudTrail logs to Amazon CloudWatch Logs is an optional downstream integration that enables real-time monitoring, metric filters, and alarms based on API activity. It does not influence whether CloudTrail records events; CloudTrail logs independently of any log destinations, so omitting this step still leaves recording fully intact. While useful for immediate alerting and operational response, this is not a required step for auditing because the core recording mechanism is CloudTrail itself, not the delivery channel.
- ✓
Configure the trail to deliver log files to an S3 bucket.
Why this is correct
Configuring the trail to deliver log files to an S3 bucket is the standard and necessary method for durable, long-term storage of CloudTrail logs, ensuring that audit records persist for compliance and forensic analysis. When you create a trail, you specify an S3 bucket where logs are stored as gzipped JSON objects; you can also apply encryption, versioning, and bucket policies to protect them. Without an S3 destination, there would be no persistent log repository, making it impossible to satisfy regulatory or historical audit requirements.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.