Courseiva
Monitoring and Logging →easyMultiple Select

DOP-C02 Monitoring and Logging Practice Question

A company is using AWS CloudTrail to log API activity in their AWS account. They want to ensure that any modification to CloudTrail configuration itself is logged and that the logs are immutable. Which combination of actions should they take? (Choose TWO.)

⚠ Common exam trap

Many exam-takers confuse CloudTrail Insights (which detects configuration changes) with the actual mechanisms for ensuring log immutability and integrity, leading them to select option E instead of the correct combination of S3 Object Lock and log file validation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Object Lock on the destination S3 bucket in governance mode.

Enabling S3 Object Lock in governance mode on the destination S3 bucket prevents any user, including the root user, from overwriting or deleting CloudTrail log objects during the retention period, ensuring immutability. Option B is correct because enabling log file validation creates a digest file that uses SHA-256 hashing to verify that log files have not been modified, deleted, or tampered with after delivery, providing integrity assurance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable S3 Object Lock on the destination S3 bucket in governance mode.

    Why this is correct

    Enabling S3 Object Lock on the destination S3 bucket is the correct way to make CloudTrail logs immutable. In governance mode, you can set a retention period and object lock protects objects from being deleted or overwritten by any user—including the AWS account root user—unless they have the `s3:BypassGovernanceRetention` permission. This ensures that the audit log remains intact for the duration of the retention period, satisfying compliance mandates that require unauditable log preservation.

  • ✓

    Enable log file validation to guarantee integrity of log files.

    Why this is correct

    Log file validation is a CloudTrail feature that generates a SHA-256 hash of each log file and stores it in a separate digest file. By validating these digests, you can cryptographically confirm that a log file hasn't been modified or deleted since it was delivered to S3. This gives you tamper evidence but does not prevent deletion; it's a verification control, not a prevention control.

  • ✗

    Disable log file validation to reduce overhead.

    Why it's wrong here

    While disabling log file validation reduces the small CPU/memory overhead of hash computation, it completely removes your ability to detect if a log file has been altered after delivery. For any security-conscious environment, the integrity guarantee of validation far outweighs the negligible performance gain. Furthermore, without validation, you have no way to prove to auditors that the logs were not tampered with.

  • ✗

    Store CloudTrail logs in a CloudWatch Logs log group with a retention policy.

    Why it's wrong here

    CloudTrail can be configured to send events to CloudWatch Logs, but CloudWatch Logs is a monitoring and log aggregation service, not an immutable archive. Log events in a log group can be manually deleted by users with `logs:DeleteLogGroup` or `logs:DeleteLogStream` permissions, and they expire automatically according to the retention policy. This makes it unsuitable for tamper-proof storage of CloudTrail logs; S3 with Object Lock is the appropriate destination for an immutable audit trail.

  • ✗

    Enable CloudTrail Insights to detect configuration changes.

    Why it's wrong here

    CloudTrail Insights captures anomalous API activity such as resource changes and high-volume events, using machine learning to detect patterns outside normal behavior. It produces a separate Insights event source and stores those events alongside regular events, but it does not add any protection to the log files themselves. Enabling Insights improves visibility, not security of the log integrity, so it cannot substitute for Object Lock or log file validation.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.