Courseiva

CCSP Cloud Security Operations Practice Question

A cloud security engineer is tasked with ensuring that all API calls made to AWS resources are logged for audit purposes. Which AWS service should be enabled to capture management events such as creating or deleting EC2 instances?

⚠ Common exam trap

Candidates often confuse AWS Config (which tracks configuration history) with CloudTrail (which tracks API calls), leading them to select AWS Config for audit logging of management events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it is specifically designed to record API activity in an AWS account, including management events such as creating or deleting EC2 instances. It captures the who, what, when, and source IP for every API call, which is essential for audit logging and compliance. AWS Config, by contrast, records resource configuration changes and compliance history, not API call logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration states and changes, not the API call events that produced them, so it cannot supply the requested audit trail. It is tempting because Config tracks resource history, and it would be correct when the requirement is assessing configuration compliance or resource relationships over time.

  • ✓

    AWS CloudTrail

    Why this is correct

    CloudTrail records API activity across AWS services, capturing management events such as RunInstances or TerminateInstances with caller identity, source IP and timestamp. Enabling it in each region and account provides the audit trail the stem requires, which service-level logs alone cannot deliver.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty analyses CloudTrail, VPC flow and DNS logs to detect threats; it consumes existing event data rather than capturing the API calls themselves. It is tempting because GuardDuty surfaces suspicious activity, and it would be correct when the requirement is continuous threat detection rather than audit logging.

  • ✗

    AWS Security Hub

    Why it's wrong here

    Security Hub aggregates and normalises findings from other services into a compliance dashboard; it does not itself record API calls. It is tempting because Security Hub presents audit-style posture views, and it would be correct when the requirement is centralised security findings and standards checks across accounts.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.