SOA-C02 Security and Compliance Practice Question
A company wants to monitor for unauthorized API calls in their AWS account. Which AWS service should they use?
⚠ Common exam trap
Test-takers frequently confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), leading them to select Config when the question specifically asks about monitoring API calls rather than resource state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records all API calls made in an AWS account, including the identity, source IP, and timestamp of each call. This enables monitoring for unauthorized API activity by analyzing the logs for suspicious patterns or unexpected actions. CloudTrail is specifically designed for auditing API usage, unlike other services that focus on resource configuration or threat detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch
Why it's wrong here
Amazon CloudWatch is fundamentally a monitoring service for operational telemetry, collecting and visualizing metrics, logs, and alarms from AWS resources and applications. While CloudWatch Logs can store CloudTrail logs if you stream them there, CloudWatch itself does not natively capture or record API calls—it only observes the resulting metrics and log events. Its purpose is to alert on operational conditions (like CPU utilization or error rates), not to provide an audit trail of who made which API call, so it cannot satisfy the requirement to monitor unauthorized API calls directly.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration management service that records resource configuration changes and evaluates those changes against desired policies, such as checking whether an S3 bucket is publicly accessible. It does not log the API calls themselves—for example, it will show that a security group rule changed, but not the identity of the caller, the API action, or the request parameters behind that change. Config offers compliance and drift detection, but unlike CloudTrail it lacks the event-level detail of each API request/response, making it unsuitable for auditing unauthorized API activity.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the correct service because it records every API call made on an account, including the identity of the caller, the source IP address, the request parameters, and the response elements, creating a complete event log for governance and auditing. It captures calls made through the AWS Management Console, SDKs, CLI, and other services, and these logs can be delivered to an S3 bucket and integrated with CloudWatch Logs for alerting. With CloudTrail, you can specifically track unauthorized API calls by analyzing the log for failed or suspicious actions, which is exactly what the company needs.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that continuously analyzes AWS CloudTrail management events, VPC flow logs, and DNS logs to identify malicious or unauthorized behavior, such as unusual API patterns or compromised credentials. However, GuardDuty does not provide a comprehensive, raw log of every API call—it only generates findings when it detects a potential threat, and it does not retain the full audit history of all API activity. While GuardDuty can help alert on suspicious API calls, it is not a complete auditing or logging solution, so it cannot replace CloudTrail for the company's requirement.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.