DOP-C02 Security and Compliance Practice Question
A company is using AWS CloudTrail to log API calls. The security team needs to ensure that log files are tamper-proof and can be used to verify integrity. Which feature should be enabled?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudTrail log file integrity validation
CloudTrail log file integrity validation uses SHA-256 hashing and digital signing to ensure logs have not been tampered with. S3 object lock prevents deletion but not modification. MFA delete protects deletion but not modification. SSE encrypts data at rest but does not protect integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server-side encryption (SSE-S3)
Why it's wrong here
Server-side encryption (SSE-S3) scrambles object contents at rest using S3-managed keys, which protects data confidentiality by preventing unauthorized parties from reading the logs. However, confidentiality and integrity are separate security goals: encryption provides no cryptographic hash or signature that lets you detect whether the log files have been modified, reordered, or sliced after they were written. An attacker with permission to write could still overwrite a log object with new encrypted content, and SSE-S3 would give you no way to notice that the data was replaced.
- ✓
CloudTrail log file integrity validation
Why this is correct
CloudTrail log file integrity validation is purpose-built for exactly this need: it delivers signed digest files to your S3 bucket that cover the log files and link together in a hash chain. Each digest contains the SHA-256 hash of the prior digest and the current log files, and is signed with a private key by CloudTrail. You can use the corresponding public key to verify both the authenticity and the integrity of the logs, which lets you detect any modification, deletion, or forgery. Enabling this feature ensures that your audit trail itself is trustworthy, which is a key defense against attackers trying to cover their tracks by altering logs.
- ✗
S3 Object Lock
Why it's wrong here
S3 Object Lock provides WORM (Write Once Read Many) protection by applying a retention mode and period that blocks object overwrite and delete requests. While this can prevent tampering after the lock is applied, it does not verify that the current object content is the same as what was originally written—there is no digest, hash, or signature generated that you can independently check. Furthermore, if an object is written without a lock or before the retention period is configured, it can still be modified, and Object Lock alone will not alert you to that change. It is a prevention control, not an integrity verification mechanism.
- ✗
MFA delete on the S3 bucket
Why it's wrong here
MFA delete is an S3 versioning feature that requires a second factor of authentication before a caller can permanently delete an object version or suspend versioning on the bucket. This reduces the risk of accidental or unauthorized deletion, but it does nothing to detect or prevent modifications to the log content itself. An authorized user with valid credentials and multi-factor authentication can still overwrite an existing log object, because MFA delete only gates delete operations, not put or post operations. It provides administrative protection, but not data integrity assurance.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.