CloudTrail is the audit log for your AWS account. Every API call — who made it, when, from what IP — gets recorded. When a question is about auditing, compliance, or “who deleted that bucket,” CloudTrail is the answer.
The distinction that earns points
CloudTrail = who did what (activity and API history). CloudWatch = how things are performing (metrics and alarms). Security investigations, compliance evidence, tracing an action to a user — that’s CloudTrail.
Test yourself
An auditor needs a record of every API call made in your account over the past 90 days, including which user made each one. What do you use?
- Amazon CloudWatch
- AWS CloudTrail
- VPC Flow Logs
- Amazon Inspector
👉 Click to reveal the answer & explanation
Correct answer: B. CloudTrail records account activity and API usage with the identity behind each call. CloudWatch (A) tracks performance metrics; VPC Flow Logs (C) capture network traffic, not API actions; Inspector (D) is vulnerability assessment.
Related topics
Amazon CloudWatch · AWS IAM · Shared Responsibility Model
Ready to pass your AWS exam?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026