Courseiva
Security and Compliance →easyMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company wants to monitor for unauthorized API calls in their AWS account. Which AWS service should they use?

⚠ Common exam trap

Test-takers frequently confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), leading them to select Config when the question specifically asks about monitoring API calls rather than resource state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records all API calls made in an AWS account, including the identity, source IP, and timestamp of each call. This enables monitoring for unauthorized API activity by analyzing the logs for suspicious patterns or unexpected actions. CloudTrail is specifically designed for auditing API usage, unlike other services that focus on resource configuration or threat detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch

    Why it's wrong here

    Amazon CloudWatch is fundamentally a monitoring service for operational telemetry, collecting and visualizing metrics, logs, and alarms from AWS resources and applications. While CloudWatch Logs can store CloudTrail logs if you stream them there, CloudWatch itself does not natively capture or record API calls—it only observes the resulting metrics and log events. Its purpose is to alert on operational conditions (like CPU utilization or error rates), not to provide an audit trail of who made which API call, so it cannot satisfy the requirement to monitor unauthorized API calls directly.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a configuration management service that records resource configuration changes and evaluates those changes against desired policies, such as checking whether an S3 bucket is publicly accessible. It does not log the API calls themselves—for example, it will show that a security group rule changed, but not the identity of the caller, the API action, or the request parameters behind that change. Config offers compliance and drift detection, but unlike CloudTrail it lacks the event-level detail of each API request/response, making it unsuitable for auditing unauthorized API activity.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the correct service because it records every API call made on an account, including the identity of the caller, the source IP address, the request parameters, and the response elements, creating a complete event log for governance and auditing. It captures calls made through the AWS Management Console, SDKs, CLI, and other services, and these logs can be delivered to an S3 bucket and integrated with CloudWatch Logs for alerting. With CloudTrail, you can specifically track unauthorized API calls by analyzing the log for failed or suspicious actions, which is exactly what the company needs.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that continuously analyzes AWS CloudTrail management events, VPC flow logs, and DNS logs to identify malicious or unauthorized behavior, such as unusual API patterns or compromised credentials. However, GuardDuty does not provide a comprehensive, raw log of every API call—it only generates findings when it detects a potential threat, and it does not retain the full audit history of all API activity. While GuardDuty can help alert on suspicious API calls, it is not a complete auditing or logging solution, so it cannot replace CloudTrail for the company's requirement.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.