Courseiva
Security and Compliance →easyMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator needs to audit all changes to IAM policies in an AWS account. Which AWS service should be used to record these changes?

⚠ Common exam trap

Many candidates confuse AWS Config with CloudTrail, thinking Config records API changes, but Config only tracks resource configuration states and compliance, not the API calls that caused those changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records API activity in an AWS account, including all IAM policy changes such as creating, updating, or deleting policies. CloudTrail captures these events as JSON logs, which can be stored in an S3 bucket for auditing and analysis. This makes it the appropriate tool for auditing changes to IAM policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is a centralized service for storing, monitoring, and querying log data from sources like EC2, Lambda, and on-premises applications. It has no native mechanism to capture IAM policy changes; it only ingests logs that are explicitly sent to it, such as application logs or CloudTrail events configured for delivery. Without a CloudTrail trail or another producer forwarding events, CloudWatch Logs will not contain any record of IAM activity. Thus, it is a log destination, not an audit source.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records the state of supported AWS resources over time, including IAM policies, and can evaluate that state against compliance rules. However, Config reports the resulting configuration—for example, the new policy document—but does not capture the identity of the API caller, the source IP, or the exact request parameters that caused the change. Config is designed for configuration governance and compliance, not for answering 'who made this change?' or providing a full API-level audit trail. For complete auditability of IAM changes, CloudTrail API events are required.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the authoritative service for auditing API activity in an AWS account, capturing every IAM API call such as PutRolePolicy, AttachUserPolicy, and CreatePolicy. Each CloudTrail event includes the IAM user or role, assumed role, session context, source IP, request parameters, response elements, and a timestamp. By default, CloudTrail provides a 90-day viewable event history, and creating a trail delivers immutable log files to an S3 bucket for long-term storage and optional CloudWatch Logs delivery. This makes CloudTrail the correct choice for auditing all IAM policy changes.

  • ✗

    Amazon S3

    Why it's wrong here

    Amazon S3 is an object storage service, not an audit log service, and it does not generate or capture API activity related to IAM policy changes. S3 can be used as a destination where CloudTrail writes log files, or it can log object-level access via S3 server access logging, but neither of those features records IAM policy modifications. Relying on S3 alone would provide no visibility into who or what changed an IAM policy. It is a passive repository for audit logs, not the mechanism that produces them.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.