A cloud administrator needs to give the security team read-only visibility into all API activity across an AWS account, including who made each call, when, and from which IP address. The records must be retained for 365 days for compliance. Which service should the administrator use?
CloudTrail records API activity in an account, capturing the identity of the caller, the time, the source IP, and the request details. Creating a trail that delivers events to an S3 bucket with a 365-day lifecycle or retention policy satisfies the compliance requirement for long-term audit visibility.
Why this answer
CloudTrail is the service purpose-built to record API activity in an AWS account, including caller identity, timestamp, and source address. Delivering those events to durable storage with a retention policy of 365 days meets both the visibility and compliance needs described.
Exam trap
The trap here is confusing configuration-change tracking or log aggregation with full API audit logging.