SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator needs to audit all changes to security groups in an AWS account. Which AWS service should be used to capture these changes?
⚠ Common exam trap
Watch out — candidates often confuse AWS Config (which tracks configuration state changes) with CloudTrail (which tracks API call provenance), leading them to choose Config for auditing changes when only CloudTrail provides the identity and source of the change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records API calls made to the AWS environment, including all CreateSecurityGroup, AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress, and DeleteSecurityGroup API actions. By enabling CloudTrail trail logging, the SysOps administrator can capture a complete audit trail of who made changes, when, and from which source IP, which is essential for security group change auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic reaching and leaving elastic network interfaces, such as source/destination addresses and ports. They record network packets, not management-plane API calls, so they cannot tell you who requested a security group change or when the change was made. Even though a security group modification can alter network behavior, that change itself is not represented in flow log entries; you would need a separate audit service to capture that API event.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the service designed to provide a complete audit trail of API activity in your account. It records every management event, including calls like AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress, and CreateSecurityGroup, along with the identity of the caller, the source IP, timestamp, and request parameters. This gives you the definitive answer to the SysOps administrator's need to audit all changes to security groups and other resources.
- ✗
CloudWatch Logs
Why it's wrong here
CloudWatch Logs is a central log aggregation service that stores and monitors log files from applications, on-premises systems, and AWS services. It does not natively generate or capture API activity; it can only ingest logs pushed to it. While CloudTrail can be configured to deliver events to CloudWatch Logs for real-time alerting, the audit capability originates from CloudTrail, not from CloudWatch Logs itself.
- ✗
AWS Config
Why it's wrong here
AWS Config monitors and records the configuration state of your AWS resources, and it can detect that a security group rule changed by comparing the previous configuration to the current one. However, it does not capture the identity of the user who made the change or the API call that caused it—it only shows the resulting resource state. For a true audit trail of all changes, with full API call details, you need CloudTrail; AWS Config serves as a complementary configuration history and compliance tool, not as the primary audit mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.