Auditing AWS API Calls and IAM Changes
A SysOps administrator needs to audit all changes to IAM resources in their AWS account. Which THREE AWS services can be used together to achieve this? (Choose THREE.)
Quick Answer
The answer is CloudTrail, AWS Config, and Amazon CloudWatch Logs. CloudTrail records all IAM API calls, providing a detailed audit trail of who made what change and when, while AWS Config continuously tracks the configuration state of IAM resources and can trigger automated rules for compliance. CloudWatch Logs then serves as the centralized storage and monitoring layer for those CloudTrail logs, enabling real-time alerting and long-term retention. On the AWS Certified SysOps Administrator Associate SOA-C02 exam, this combination tests your understanding of the three pillars of auditing: recording (CloudTrail), tracking (Config), and monitoring (CloudWatch Logs). A common trap is choosing GuardDuty, which is for threat detection, not change auditing, or Trusted Advisor, which is for best-practice recommendations. Memory tip: think "Record, Track, Watch" — CloudTrail records, Config tracks, CloudWatch watches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail (A) is correct because it records every API call that modifies IAM resources (CreateUser, AttachRolePolicy, PutRolePolicy, etc.) as management events, providing the raw audit trail of who did what and when. AWS Config (C) is correct because it continuously records IAM resource configurations and their change history, letting you see the before/after state of users, roles, and policies and evaluate them against rules. Amazon CloudWatch Logs (E) is correct because CloudTrail can deliver its event logs to a CloudWatch Logs log group, where you can retain, search, and set metric filters/alarms on IAM change events. Amazon GuardDuty (B) is a threat-detection service that analyzes logs for malicious behavior, not a change-auditing mechanism, and AWS Trusted Advisor (D) provides best-practice checks and recommendations rather than a record of IAM changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail records every IAM API call as a management event, capturing who changed which resource, when, and from where. It supplies the authoritative change history that audit tooling and log analysis consume to reconstruct all IAM modifications across the account.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty detects malicious activity and anomalous behaviour from logs such as CloudTrail, but it does not itself record or retain IAM change events. It is tempting because it consumes CloudTrail data, yet that is threat detection, not the audit trail required here.
- ✓
AWS Config
Why this is correct
AWS Config continuously records resource configuration changes, including IAM policies, users and roles, and retains a timestamped history. Combined with CloudTrail for API attribution and CloudWatch or SNS for alerting, it satisfies the requirement to audit all IAM resource changes.
- ✗
AWS Trusted Advisor
Why it's wrong here
Trusted Advisor inspects cost, security, fault tolerance and service limits, but records no API activity and cannot report IAM resource changes. It is tempting because its security checks flag permissive IAM policies, which is advisory assessment rather than change auditing.
- ✓
Amazon CloudWatch Logs
Why this is correct
CloudWatch Logs stores the log streams that CloudTrail delivers, enabling retention, querying and alerting on IAM change events. Combined with CloudTrail capturing the API activity and AWS Config recording resource states, it satisfies the requirement to audit all IAM resource changes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A SysOps administrator needs to audit all API calls made in the AWS account, including actions performed by the root user. Which service should be enabled?
easy- A.AWS Config
- B.VPC Flow Logs
- ✓ C.AWS CloudTrail
- D.Amazon CloudWatch Logs
Why C: AWS CloudTrail records all API calls made in an AWS account, including those made by the root user, IAM users, roles, and AWS services. It provides a detailed audit trail of actions taken, which is essential for security and compliance auditing. Enabling CloudTrail in all regions ensures comprehensive coverage.
Variation 2. A SysOps administrator needs to audit all changes to IAM policies in an AWS account. Which AWS service should be used to record these changes?
easy- A.Amazon CloudWatch Logs
- B.AWS Config
- ✓ C.AWS CloudTrail
- D.Amazon S3
Why C: AWS CloudTrail is the correct service because it records API activity in an AWS account, including all IAM policy changes such as creating, updating, or deleting policies. CloudTrail captures these events as JSON logs, which can be stored in an S3 bucket for auditing and analysis. This makes it the appropriate tool for auditing changes to IAM policies.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.