DVA-C02 Security Practice Question
A company is using Amazon S3 to store sensitive documents. The security team requires that all access to the bucket be logged for audit purposes, but the company wants to avoid AWS CloudTrail data event charges and needs detailed HTTP request/response records. Which feature should be enabled?
⚠ Common exam trap
Candidates often confuse S3 server access logging with AWS CloudTrail. While CloudTrail is the standard for API auditing, CloudTrail data events (required for object-level logging like GetObject/PutObject) incur significant costs at scale. S3 server access logging is the cost-effective choice when you need to log S3 HTTP requests and want to avoid CloudTrail data event charges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
S3 server access logging
S3 server access logging provides detailed records for requests made to an S3 bucket, including the requester, bucket name, request time, action, and response status. Unlike AWS CloudTrail data events, which incur additional charges per 100,000 events, S3 server access logging is free to enable (you only pay for the storage of the log files). This makes it the ideal choice for detailed HTTP-level logging without extra service costs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
S3 server access logging
Why this is correct
S3 server access logging is the correct mechanism for recording detailed information about every request made to an S3 bucket, including successful and failed requests. These logs capture crucial details such as the requester's IP address, the operation performed (e.g., GET, PUT), the object key, the time of the request, and HTTP status codes. This comprehensive logging is essential for auditing access to sensitive documents and understanding usage patterns directly at the object level.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a centralized logging service primarily used for collecting and monitoring logs from various AWS services and applications, such as EC2 instances, Lambda functions, or custom application logs. While other AWS services can integrate with CloudWatch Logs, S3 server access logs are natively delivered directly to a designated S3 bucket. CloudWatch Logs does not directly capture S3 object access events as its primary function; it would require an intermediary service or a different logging mechanism to forward S3 access data.
- ✗
S3 Inventory
Why it's wrong here
S3 Inventory provides a flat file list of objects and their corresponding metadata for a bucket or a specific prefix, delivered daily or weekly to another S3 bucket. Its purpose is to help manage and audit storage by providing insights into object properties like size, storage class, and encryption status. However, S3 Inventory does not record individual access events, user requests, or operational details like read/write actions, making it unsuitable for tracking who accessed sensitive documents.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API calls made to AWS services, including S3, providing a history of management events (e.g., CreateBucket, DeleteBucket) and optionally data events (e.g., GetObject, PutObject). While CloudTrail can log object-level API calls, it focuses on the 'who, what, when, and where' of API interactions, primarily for governance, compliance, and auditing of actions taken against S3. S3 server access logs, conversely, provide more granular details for *all* object access requests, including anonymous requests and specific HTTP request details, which are not always fully captured or are more costly to obtain via CloudTrail data events for every single access.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.