SOA-C02 Security and Compliance Practice Question
Network Topology
Refer to the exhibit. A SysOps administrator runs the AWS CLI command to check the event selectors for a CloudTrail trail. What does the output indicate?
⚠ Common exam trap
SOA-C02 often tests the interpretation of CloudTrail event selector output; candidates may assume data events are included by default, but they are not unless explicitly configured.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The trail logs all management events.
The exhibit shows the output of the AWS CLI command to describe event selectors for a CloudTrail trail. The output indicates that the trail is configured to log all management events, as specified by the 'IncludeManagementEvents' field set to true and no data event selectors defined. Therefore, the trail logs all management events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The trail logs all management events.
Why this is correct
The trail logs all management events because the IncludeManagementEvents field is set to true and ReadWriteType is set to All, which captures both read and write operations on AWS resources. The JSON configuration confirms this is the default and intended behavior for a management-event-only trail, so any claim that it logs only a subset or additional data events would be incorrect.
- ✗
The trail logs both management and data events.
Why it's wrong here
The trail does not log both management and data events because DataResources is an empty list. In CloudTrail, data events (such as S3 object-level actions, Lambda invocations, or DynamoDB row changes) are only recorded when you explicitly specify the resource types whose activities you want to capture; with no DataResources defined, no data event selectors are active, so only management events are delivered to the trail.
- ✗
The trail logs all data events.
Why it's wrong here
The trail logs no data events at all because the DataResources array is empty. To log all data events, the trail would need at least one data event selector that specifies 'ALL' for a resource type (for example, an S3 bucket with a prefix that covers all objects), or include a set of specific resources; since none are present, the trail captures management events exclusively and cannot be described as logging all data events.
- ✗
The trail logs only write management events.
Why it's wrong here
The trail does not log only write management events because the ReadWriteType attribute is set to All, which explicitly instructs CloudTrail to include both read-only events (for example, Describe* or List* API calls) and write events (such as Create* or Delete* API calls). If the trail were restricted to writes, ReadWriteType would be set to WriteOnly, so the existing configuration clearly captures the full spectrum of management activity.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.