Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator needs to audit all IAM user activity in the AWS account for the last 90 days. Which AWS service should be used?

⚠ Common exam trap

Many candidates confuse AWS Config's configuration tracking with CloudTrail's API activity logging, or assume GuardDuty's threat detection includes a built-in audit trail for all user actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records all API calls made by IAM users, including console sign-in events, CLI commands, and SDK actions, and retains these logs for up to 90 days by default in the event history. This allows the SysOps administrator to audit all IAM user activity over the last 90 days without additional configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configurations, configuration history, and configuration item changes (e.g., a security group rule being modified or an EC2 instance type changing). It does not capture the API calls IAM users make or the identity context behind those actions, so it cannot serve as an audit trail of IAM user activity. AWS Config evaluates resources against rules for compliance, but it is not an operational audit log.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor provides best-practice recommendations across cost optimization, performance, security, fault tolerance, and service limits. It performs periodic checks, such as whether MFA is enabled on the root account or whether unused IAM credentials exist, but it does not record or log individual user actions. Trusted Advisor is a guidance tool, not an audit mechanism, so it cannot tell you who did what or when.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the correct service for auditing IAM user activity because it records every AWS API call as a CloudTrail event, including who made the request (IAM user or role), when it was made, from which source IP, and what action was performed. By enabling a trail that delivers events to an S3 bucket (and optionally CloudWatch Logs), you capture a complete, tamper-evident history of all IAM user activity for security analysis and operational troubleshooting. CloudTrail also supports logging both management events, such as CreateUser or AttachUserPolicy, and data events, giving you the audit coverage necessary to answer 'who did what' in your account.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a continuous threat detection service that uses machine learning, anomaly detection, and threat intelligence to identify malicious or unauthorized behavior, such as unusual API calls, compromised credentials, or cryptocurrency mining. It generates security findings when it detects suspicious activity, but it does not maintain a comprehensive record of every IAM user action. GuardDuty complements CloudTrail by analyzing the logs CloudTrail produces, but it is not itself an auditing tool for user activity.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.