Courseiva
Security and Compliance →mediumMultiple Select

SOA-C02 Security and Compliance Practice Question

A SysOps administrator is configuring CloudTrail to log all management events and data events for S3 buckets. Which of the following are true about CloudTrail logging? (Choose THREE.)

⚠ Common exam trap

It's easy for candidates to assume data events are logged by default because S3 is a core service, but CloudTrail requires explicit opt-in for data events, and management events are the only ones enabled by default.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudTrail logs include the identity of the user who made the API call

CloudTrail logs include the identity of the user or role that made the API call, captured as the `userIdentity` element in the log record. This element contains details such as the ARN, access key ID, and whether the call was made by an IAM user, federated user, or assumed role, enabling full auditability of who performed each action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data events for S3 are logged by default for all buckets

    Why it's wrong here

    Data events for S3 are not logged by default. When you create a CloudTrail trail, only management events are enabled; data plane operations such as GetObject, PutObject, and DeleteObject require you to explicitly add an S3 bucket and select data event types. Without this configuration, no S3 object-level activity is recorded.

  • ✓

    CloudTrail logs include the identity of the user who made the API call

    Why this is correct

    CloudTrail logs capture the full userIdentity element for every API call, including the IAM user or role, root user, federated user, or assumed role. It also records the access key ID, source IP address, user agent, and session context, enabling you to determine exactly who performed an action. This makes CloudTrail essential for security auditing and governance.

  • ✓

    Management events are logged by default

    Why this is correct

    Management events, sometimes called control plane events, are logged by default in every CloudTrail trail. These events include operations like creating, deleting, or modifying AWS resources, for both read and write API calls. You do not need to configure anything to collect these events when you create a trail.

  • ✗

    CloudTrail can log events for all AWS services automatically

    Why it's wrong here

    CloudTrail cannot automatically log events for all AWS services because not every service publishes API calls to CloudTrail. Only AWS services that have integrated their APIs with CloudTrail are supported, and even then, you must create a trail or event data store to receive the events. The claim that all services are covered automatically is incorrect.

  • ✓

    CloudTrail can deliver log files to CloudWatch Logs for real-time analysis

    Why this is correct

    CloudTrail can be configured to deliver log files to CloudWatch Logs, allowing you to perform real-time analysis and set up metric filters and alarms on API activity. This integration is separate from S3 delivery and helps you monitor suspicious behavior or operational issues as they occur. It is a standard feature supported by CloudTrail trails.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SysOps administrator needs to ensure that all API calls made to AWS are logged for auditing purposes. Which AWS service should be enabled to capture management events?

medium
  • ✓ A.AWS CloudTrail
  • B.S3 server access logs
  • C.VPC Flow Logs
  • D.Amazon CloudWatch Logs

Why A: AWS CloudTrail is the service specifically designed to record API activity in an AWS account, including management events (control plane operations) such as creating, modifying, or deleting resources. It captures the identity of the caller, the time of the call, the source IP address, and other details, making it the correct choice for auditing API calls. CloudTrail logs can be delivered to an S3 bucket and optionally to CloudWatch Logs for further analysis.

Variation 2. Refer to the exhibit. A SysOps administrator runs the AWS CLI command to check the event selectors for a CloudTrail trail. What does the output indicate?

medium
  • ✓ A.The trail logs all management events.
  • B.The trail logs both management and data events.
  • C.The trail logs all data events.
  • D.The trail logs only write management events.

Why A: The exhibit shows the output of the AWS CLI command to describe event selectors for a CloudTrail trail. The output indicates that the trail is configured to log all management events, as specified by the 'IncludeManagementEvents' field set to true and no data event selectors defined. Therefore, the trail logs all management events.

Variation 3. A SysOps administrator is investigating an unauthorized stop of an EC2 instance. The CloudTrail log entry shows the event. What is the first step to determine if the action was authorized?

medium
  • A.Check the S3 bucket where CloudTrail logs are stored.
  • B.Verify the source IP address belongs to the company.
  • C.Check the EC2 instance's state change history.
  • ✓ D.Check the IAM permissions of the user 'Admin' at the time of the event.

Why D: The first step in determining whether an EC2 stop action was authorized is to examine the IAM permissions of the principal (user 'Admin') at the time of the event — if the identity lacked ec2:StopInstances permission, the action was unauthorized. CloudTrail records the API call and the identity, but authorization is determined by IAM policy evaluation. This directly answers whether the action was permitted.

Variation 4. A SysOps administrator runs the AWS CLI command shown in the exhibit. What is the purpose of this command?

medium
  • ✓ A.To retrieve details about the most recent console login events.
  • B.To count the number of console logins in the last 5 minutes.
  • C.To retrieve a list of all API calls made by the user john.doe.
  • D.To disable CloudTrail logging for console login events.

Why A: The AWS CLI command in the exhibit is `aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=ConsoleLogin --max-results 5` (or similar). This command queries CloudTrail's event history for ConsoleLogin events, returning details about the most recent console login events. It does not count logins, list all API calls, or disable logging.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.