CloudTrail is the audit log for your AWS account. Every API call — who made it, when, from what IP — gets recorded. When a question is about auditing, compliance, or “who deleted that bucket,” CloudTrail is the answer.

The distinction that earns points

CloudTrail = who did what (activity and API history). CloudWatch = how things are performing (metrics and alarms). Security investigations, compliance evidence, tracing an action to a user — that’s CloudTrail.

Test yourself

Practice question

An auditor needs a record of every API call made in your account over the past 90 days, including which user made each one. What do you use?

  1. Amazon CloudWatch
  2. AWS CloudTrail
  3. VPC Flow Logs
  4. Amazon Inspector
👉 Click to reveal the answer & explanation

Correct answer: B. CloudTrail records account activity and API usage with the identity behind each call. CloudWatch (A) tracks performance metrics; VPC Flow Logs (C) capture network traffic, not API actions; Inspector (D) is vulnerability assessment.

Related topics

Amazon CloudWatch · AWS IAM · Shared Responsibility Model

CloudExamPro Premium

Ready to pass your AWS exam?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

See the Practice Exam Packs →

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access