AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

An auditor reviewing CloudTrail wants to see individual S3 GetObject and PutObject API calls made against a specific bucket, which are not captured by default in a standard trail. Which type of CloudTrail event must be enabled to capture this activity?

  1. AManagement events
  2. BConfig events
  3. CInsight events
  4. DData events
Show answer & explanation

Correct answer: D. Data events

CloudTrail management events (enabled by default) record control plane operations like creating or deleting resources. Data events capture object-level operations such as S3 GetObject/PutObject or Lambda invocations, and must be explicitly enabled because of their high volume. Insight events detect unusual API call rate patterns, and 'Config events' is not a CloudTrail event type.

Why the other options are wrong

  • A. Management events cover control plane actions like bucket creation, not object-level reads/writes.
  • B. There is no CloudTrail event type called 'Config events'.
  • C. Insight events detect anomalous API activity patterns, not specific object operations.

CloudTrail Data Events

CloudTrail events that record object-level operations (e.g., S3 GetObject/PutObject, Lambda Invoke) which are not logged by default.

  • Must be explicitly enabled per resource
  • Higher volume/cost than management events
  • Management events are enabled by default and cover control plane actions

Memory trick: Data events = the 'data plane' details, off by default

More Security and Compliance questions