Courseiva
Security and Compliance →easyMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator needs to audit all API calls made in the AWS account, including actions performed by the root user. Which service should be enabled?

⚠ Common exam trap

SOA-C02 often tests the difference between CloudTrail (API auditing) and AWS Config (resource configuration history); candidates may confuse the two, especially when the question mentions 'audit' and 'API calls'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail records all API calls made in an AWS account, including those made by the root user, IAM users, roles, and AWS services. It provides a detailed audit trail of actions taken, which is essential for security and compliance auditing. Enabling CloudTrail in all regions ensures comprehensive coverage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config fails because it tracks changes to AWS resource configurations and evaluates compliance against desired states, rather than recording a history of all API calls made in the account. The question specifically asks to audit *API calls*, including root user actions, which Config does not provide. It is tempting as Config *does* perform auditing, but for resource configurations. It would be the correct choice for continuously monitoring resource configuration changes or assessing compliance with specific configuration rules.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture network-level metadata about IP traffic flowing to and from elastic network interfaces in a VPC, such as source/destination IPs, ports, protocols, and packet/byte counts. They operate at the data plane and do not record the identity of users, the API operations invoked, or any control-plane activity like IAM or root user actions. Therefore, they are unsuitable for auditing API calls because they lack application-layer context and user attribution entirely.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the definitive service for auditing API activity because it records a detailed history of every public AWS API call made on the account, including the identity of the caller, the API operation, parameters, source IP, and event time. It captures management events from all regions and by default retains the last 90 days in the event history, while a trail can deliver logs to S3 for long-term storage, enabling governance, security analysis, and tracking of root user actions. It is the correct service when you need to answer 'who did what, when, and how' across the entire AWS control plane.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is designed to ingest, store, and query log files from applications, EC2 instances, and AWS services, making it a tool for operational observability and troubleshooting. It does not natively generate API call records; it can only consume CloudTrail events if you explicitly configure a trail to stream them there, and it lacks the built-in audit history, IAM attribution, and event structure that CloudTrail provides. Using CloudWatch Logs alone would not satisfy an audit requirement because it is a log management platform, not a source of API activity data.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.