Courseiva

DOP-C02 Incident and Event Response Practice Question

A company uses Amazon CloudWatch Logs to collect application logs from EC2 instances. The security team requires that log data be encrypted at rest using a customer-managed AWS KMS key. The logs are currently being delivered, but they are not encrypted. What is the most likely reason?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The KMS key policy does not allow the CloudWatch Logs service principal

For CloudWatch Logs to encrypt log data at rest with a customer-managed KMS key, the key policy must grant the CloudWatch Logs service principal the necessary permissions (kms:Encrypt, kms:Decrypt, etc.). If the key policy does not include this, CloudWatch Logs can still ingest the logs but cannot encrypt them, resulting in unencrypted logs. Option A is incorrect: the IAM role for the EC2 instance does not need kms:Encrypt permissions for server-side encryption; that is handled by the CloudWatch Logs service using the key policy. Option B is incorrect because encryption is configured at the log group level, not in the agent. Option C would cause delivery failures, not just lack of encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IAM role for the EC2 instance does not have kms:Encrypt permission

    Why it's wrong here

    The IAM role attached to the EC2 instance only needs permissions to call CloudWatch Logs APIs like PutLogEvents, not kms:Encrypt. When the log group is associated with a KMS key, the CloudWatch Logs service itself uses the key to encrypt log data under the service principal, and authorization is governed by the KMS key policy. The instance's IAM role is irrelevant to the actual encryption operation, so missing kms:Encrypt there does not explain unencrypted logs.

  • ✗

    The CloudWatch Logs agent is not configured to encrypt logs

    Why it's wrong here

    Encryption for CloudWatch Logs is configured at the log group level with a KMS key, not in the CloudWatch Logs agent. The agent only forwards log events to the CloudWatch Logs API; it has no awareness of or control over server-side encryption. Therefore, the agent's configuration has no impact on whether the log group encrypts data, making this option an incorrect cause.

  • ✗

    The KMS key is disabled

    Why it's wrong here

    If the KMS key were disabled, CloudWatch Logs would be unable to call kms:Encrypt with that key. In practice, this would cause PutLogEvents requests to fail with a KMSException, and no log events would be accepted or delivered. Since logs are successfully being delivered, the key itself must be enabled and usable; a disabled key would not result in logs silently stored in plaintext.

  • ✓

    The KMS key policy does not allow the CloudWatch Logs service principal

    Why this is correct

    This is the correct cause. CloudWatch Logs acts under the service principal logs.amazonaws.com when performing server-side encryption with an AWS KMS customer managed key. If the KMS key policy does not include a statement granting this principal the kms:Encrypt and kms:DescribeKey actions (and denies are absent), the service cannot encrypt the log events. In such a case, log delivery may continue to succeed but the data is stored without the intended encryption, exactly matching the symptom described.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.