Courseiva
Security and Compliance →mediumMultiple Select

SOA-C02 Security and Compliance Practice Question

Match each AWS service with its primary security compliance function. (Drag each service to its correct function.) (Choose 4.)

⚠ Common exam trap

A common mix-up: candidates confuse AWS CloudTrail with AWS Config, thinking both are for monitoring configuration changes, but CloudTrail focuses on API activity logging while Config tracks resource configuration state changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail -> Detect unauthorized API calls

AWS CloudTrail is the service that records API activity in your AWS account, including both management and data events. By enabling CloudTrail, you can detect unauthorized API calls by analyzing the recorded events for actions that were not initiated by authorized users or services, such as an IAM user making a call from an unexpected IP address or using an unknown user agent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail -> Detect unauthorized API calls

    Why this is correct

    AWS CloudTrail is the compliance service that records every API action made in an AWS account, capturing the identity, time, source IP, and request parameters for each call. This complete audit trail enables security teams to detect unauthorized or anomalous API activity, such as a user attempting to access resources without permission or a compromised credential generating unusual calls. It is the first place to investigate security incidents and prove compliance for regulatory audits, making it correctly matched to 'Detect unauthorized API calls'.

  • ✓

    AWS Config -> Monitor resource configuration changes

    Why this is correct

    AWS Config continuously records the configuration state of AWS resources and evaluates those configurations against desired rules, such as ensuring S3 buckets are not publicly readable or that security groups do not allow unrestricted SSH. It provides a timeline of configuration changes, which helps detect drift from compliant baselines and supports governance, security, and compliance auditing. Unlike GuardDuty or CloudTrail, Config focuses on what resources are configured to be, not on the activity happening within them, aligning directly with 'Monitor resource configuration changes'.

  • ✓

    Amazon GuardDuty -> Identify malicious activity

    Why this is correct

    Amazon GuardDuty is a threat detection service that applies machine learning, anomaly detection, and intel feeds to analyze CloudTrail management events, VPC Flow Logs, and DNS logs for signs of malicious activity. It identifies threats such as compromised EC2 instances, unauthorized network connections, or cryptocurrency mining within your environment, and generates prioritized findings. This service is purpose-built for active threat identification, not for auditing or configuration compliance, so its primary security compliance function is 'Identify malicious activity'.

  • ✓

    Amazon Macie -> Discover sensitive data in S3

    Why this is correct

    Amazon Macie uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data, such as personally identifiable information (PII) or financial account numbers, stored in Amazon S3 buckets. It evaluates data risk by analyzing bucket policies, encryption settings, and the sensitivity of the content, generating alerts when sensitive data is exposed or unencrypted. Macie's core purpose is data privacy and compliance, specifically focusing on the data itself rather than API calls, configurations, or threats, which matches 'Discover sensitive data in S3'.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.