Courseiva
Security and Compliance →mediumMultiple Select

DOP-C02 Security and Compliance Practice Question

A company is using AWS CloudTrail to log API events. The security team wants to ensure that log files are tamper-proof and available for incident investigation. Which TWO actions should be taken? (Choose TWO.)

⚠ Common exam trap

The trap is equating encryption with tamper-proofing — candidates pick SSE-S3 or KMS thinking encryption protects integrity, when only log file validation and Object Lock actually prevent or detect modification and deletion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable CloudTrail log file validation.

Option C is correct because enabling CloudTrail log file validation generates a digest file for each log file, allowing you to verify that logs have not been altered or deleted after delivery. Option D is correct because S3 Object Lock enforces WORM (write once, read many) protection, preventing log files from being overwritten or deleted during a defined retention period, which directly supports tamper-proofing and availability for investigations. Option A is not correct because CloudWatch Logs is a monitoring/log aggregation service and does not by itself provide tamper-proofing or immutability for CloudTrail log files. Option B is not correct because SSE-S3 only provides encryption at rest and does not prevent modification or deletion of log files. Option E is not correct because AWS KMS encryption, while stronger in key control, still does not enforce immutability or tamper resistance on its own.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store logs in Amazon CloudWatch Logs.

    Why it's wrong here

    CloudTrail can be configured to stream audit events to Amazon CloudWatch Logs for real-time monitoring, but that destination is not immutable. CloudWatch Logs lacks a cryptographic hash chain or object-level write-once retention, so any identity with logs:DeleteLogStream or PutLogEvents permissions can alter or remove events. It also stores events with coarse metadata rather than the original log file container, making forensic validation difficult. Therefore, it is not a suitable control for tamper-proof storage.

  • ✗

    Enable server-side encryption with S3-managed keys (SSE-S3).

    Why it's wrong here

    SSE-S3 encrypts log files at rest using AES-256 with keys managed by S3, but encryption only addresses confidentiality. It does not prevent an authorized (or compromised) principal with s3:PutObject or s3:DeleteObject permissions from overwriting or deleting log files. There is no integrity verification or write-once enforcement. Consequently, SSE-S3 alone would fail to protect against tampering.

  • ✓

    Enable CloudTrail log file validation.

    Why this is correct

    CloudTrail's log file validation writes digest files to the same S3 bucket every hour, each containing a SHA-256 hash of the current log file and a reference to the previous digest. This creates an unbroken hash chain that you can use to verify whether any log file was altered, deleted, or replayed after delivery. To use it, enable the validation and store digests in a separate prefix with a restrictive bucket policy. It is a detective control that detects tampering after the fact, making it the direct answer to protecting log integrity.

  • ✓

    Enable S3 Object Lock on the S3 bucket storing the logs.

    Why this is correct

    S3 Object Lock enforces a write-once-read-many (WORM) policy on the log bucket using retention modes (Compliance or Governance) or legal holds. In Compliance mode, even the root user cannot delete or overwrite objects until the retention period expires, which prevents both accidental and malicious tampering. It works alongside CloudTrail's digest validation to provide a preventive control, because it blocks modification or deletion rather than merely detecting it. Note that you must configure the bucket with Object Lock enabled before logs are written.

  • ✗

    Use AWS KMS to encrypt the logs.

    Why it's wrong here

    AWS KMS provides envelope encryption through customer-managed or AWS-managed KMS keys, but encrypting logs does not protect their integrity. A principal with kms:Decrypt and s3:PutObject permissions can still decrypt, modify, and re-encrypt a log file without detection. KMS also introduces additional operational complexity, such as ensuring CloudTrail and S3 have access to the key. Encryption alone is a confidentiality control, not a tamper-evidence control.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.