Courseiva
Security and Compliance →hardMultiple Select

Auditing AWS API Calls and IAM Changes

A SysOps administrator needs to audit all changes to IAM resources in their AWS account. Which THREE AWS services can be used together to achieve this? (Choose THREE.)

Quick Answer

The answer is CloudTrail, AWS Config, and Amazon CloudWatch Logs. CloudTrail records all IAM API calls, providing a detailed audit trail of who made what change and when, while AWS Config continuously tracks the configuration state of IAM resources and can trigger automated rules for compliance. CloudWatch Logs then serves as the centralized storage and monitoring layer for those CloudTrail logs, enabling real-time alerting and long-term retention. On the AWS Certified SysOps Administrator Associate SOA-C02 exam, this combination tests your understanding of the three pillars of auditing: recording (CloudTrail), tracking (Config), and monitoring (CloudWatch Logs). A common trap is choosing GuardDuty, which is for threat detection, not change auditing, or Trusted Advisor, which is for best-practice recommendations. Memory tip: think "Record, Track, Watch" — CloudTrail records, Config tracks, CloudWatch watches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail (A) is correct because it records every API call that modifies IAM resources (CreateUser, AttachRolePolicy, PutRolePolicy, etc.) as management events, providing the raw audit trail of who did what and when. AWS Config (C) is correct because it continuously records IAM resource configurations and their change history, letting you see the before/after state of users, roles, and policies and evaluate them against rules. Amazon CloudWatch Logs (E) is correct because CloudTrail can deliver its event logs to a CloudWatch Logs log group, where you can retain, search, and set metric filters/alarms on IAM change events. Amazon GuardDuty (B) is a threat-detection service that analyzes logs for malicious behavior, not a change-auditing mechanism, and AWS Trusted Advisor (D) provides best-practice checks and recommendations rather than a record of IAM changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail records every IAM API call as a management event, capturing who changed which resource, when, and from where. It supplies the authoritative change history that audit tooling and log analysis consume to reconstruct all IAM modifications across the account.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty detects malicious activity and anomalous behaviour from logs such as CloudTrail, but it does not itself record or retain IAM change events. It is tempting because it consumes CloudTrail data, yet that is threat detection, not the audit trail required here.

  • ✓

    AWS Config

    Why this is correct

    AWS Config continuously records resource configuration changes, including IAM policies, users and roles, and retains a timestamped history. Combined with CloudTrail for API attribution and CloudWatch or SNS for alerting, it satisfies the requirement to audit all IAM resource changes.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    Trusted Advisor inspects cost, security, fault tolerance and service limits, but records no API activity and cannot report IAM resource changes. It is tempting because its security checks flag permissive IAM policies, which is advisory assessment rather than change auditing.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    CloudWatch Logs stores the log streams that CloudTrail delivers, enabling retention, querying and alerting on IAM change events. Combined with CloudTrail capturing the API activity and AWS Config recording resource states, it satisfies the requirement to audit all IAM resource changes.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SysOps administrator needs to audit all API calls made in the AWS account, including actions performed by the root user. Which service should be enabled?

easy
  • A.AWS Config
  • B.VPC Flow Logs
  • ✓ C.AWS CloudTrail
  • D.Amazon CloudWatch Logs

Why C: AWS CloudTrail records all API calls made in an AWS account, including those made by the root user, IAM users, roles, and AWS services. It provides a detailed audit trail of actions taken, which is essential for security and compliance auditing. Enabling CloudTrail in all regions ensures comprehensive coverage.

Variation 2. A SysOps administrator needs to audit all changes to IAM policies in an AWS account. Which AWS service should be used to record these changes?

easy
  • A.Amazon CloudWatch Logs
  • B.AWS Config
  • ✓ C.AWS CloudTrail
  • D.Amazon S3

Why C: AWS CloudTrail is the correct service because it records API activity in an AWS account, including all IAM policy changes such as creating, updating, or deleting policies. CloudTrail captures these events as JSON logs, which can be stored in an S3 bucket for auditing and analysis. This makes it the appropriate tool for auditing changes to IAM policies.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.