SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator needs to track changes to security groups in the AWS account. Which AWS service should be used to record configuration changes and provide a history of security group modifications?
⚠ Common exam trap
It's easy for candidates to confuse AWS CloudTrail (which logs API calls) with AWS Config (which records resource configuration state and history), leading them to choose CloudTrail for change tracking when Config is the service designed for configuration history and compliance auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it provides a detailed inventory of AWS resources, records configuration changes, and maintains a historical timeline of those changes. For security groups, AWS Config can track modifications such as rule additions, deletions, or updates, and it can trigger evaluations against desired configurations. This makes it the ideal service for auditing and compliance use cases involving security group changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor is an advisory service that evaluates your AWS environment against best practices and provides recommendations for cost optimization, performance, security, and fault tolerance. However, it does not maintain a historical record of configuration changes or capture the state of security group rules over time. You can see a security check flag an open port, but you cannot use Trusted Advisor to trace when or how that security group rule was added, modified, or removed.
- ✗
Amazon CloudWatch
Why it's wrong here
Amazon CloudWatch is designed for monitoring operational health via metrics, logs, and alarms, not for recording infrastructure configuration state. While CloudWatch Logs might capture application or VPC flow logs, it does not natively store a structured, queryable history of security group configuration changes. CloudWatch alarms can react to metric thresholds, but they cannot tell you the prior rules of a security group or show a timeline of its configuration over time.
- ✓
AWS Config
Why this is correct
AWS Config is the correct service because it continuously records configuration items for supported resources, including security groups, and maintains a configuration history. When a security group rule is added or removed, AWS Config generates a configuration item and allows you to review the previous and new state using the configuration timeline. It also enables compliance rules to detect and evaluate changes, making it the definitive service for tracking and auditing security group changes.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API calls made in your account, such as AuthorizeSecurityGroupIngress or RevokeSecurityGroupIngress, along with the identity, time, and request parameters. However, CloudTrail does not store the resulting configuration state of the security group; it only logs the event that attempted the change. To track the actual configuration history, you would need to parse and reconstruct state from multiple CloudTrail events, which is less reliable and more complex than using AWS Config's native configuration timeline.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.