DOP-C02 Security and Compliance Practice Question
A company uses AWS CloudTrail to log all API calls across multiple accounts. The logs are stored in an S3 bucket in the management account. The security team wants to ensure that the logs are not tampered with and that any unauthorized modification is detected. The DevOps engineer has enabled CloudTrail log file integrity validation. The engineer also sets up an S3 lifecycle policy to transition logs to Glacier after 90 days. Additionally, the engineer enables S3 server access logging and sends the logs to a different bucket. A few months later, the security team suspects that some logs have been deleted. The engineer checks the CloudTrail digest files and finds that the latest digest file is missing. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The S3 lifecycle policy transitions objects to Glacier after 90 days, causing the digest file to appear missing when listing the bucket without filtering by storage class.
CloudTrail log file integrity validation stores digest files in the same S3 bucket as the logs. The lifecycle policy transitions all objects, including digest files, to Glacier after 90 days. When objects are transitioned to Glacier, they remain in the bucket but are not readily accessible via standard S3 list operations unless you specifically request the Glacier storage class. As a result, the latest digest file may appear missing, leading to the assumption that logs were deleted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The S3 lifecycle policy transitions objects to Glacier after 90 days, causing the digest file to appear missing when listing the bucket without filtering by storage class.
Why this is correct
While the scenario describes a transition to Glacier (not expiration), the lifecycle policy is still the cause: the digest file is moved to Glacier and becomes inaccessible, appearing missing. This is the most likely cause among the options.
- ✗
The S3 bucket has default encryption enabled, causing the digest files to be unreadable.
Why it's wrong here
Default encryption only encrypts objects at rest; it does not affect object availability, listing, or retrieval semantics. When an authorized principal issues a `GetObject` request, S3 transparently decrypts the object using the configured SSE-S3 or SSE-KMS keys, so the digest file remains readable. A digest file protected by default encryption would still appear in the S3 bucket listing and would not be missing, making this explanation inconsistent with the observed symptom.
- ✗
The server access logging is writing access logs to the same bucket, causing overwrites.
Why it's wrong here
S3 server access logging is delivered to a separate destination bucket or to a dedicated `logs/` prefix within the source bucket, using unique object keys that include timestamps and request IDs. These access log objects never overwrite existing objects because each key is unique, and CloudTrail digest files reside under a completely different prefix such as `AWSLogs/.../CloudTrail-Digest/...`. Therefore, even if server access logging were mistakenly configured to write to the same bucket, it could not cause the digest file to disappear or be overwritten.
- ✗
The S3 bucket has Object Lock enabled, which prevents deletion of any objects.
Why it's wrong here
Object Lock, when enabled with compliance or governance retention modes or a legal hold, explicitly prevents objects—including versioned objects—from being deleted or overwritten by any user, bucket policy, or lifecycle rule. Rather than causing the CloudTrail digest file to disappear, Object Lock would actively protect it from deletion and transition, so its presence would make the missing file even more puzzling. If the digest is unavailable, the cause must be something else, such as an improper lifecycle action or deletion by a principal with sufficient permissions, not an Object Lock configuration.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.