DOP-C02 Security and Compliance Practice Question
A company uses AWS Organizations with 20 accounts. The Security team has configured AWS CloudTrail to deliver logs from all accounts to a central S3 bucket (central-bucket). The bucket policy allows CloudTrail to write objects and uses SSE-S3 encryption. Recently, auditors found that some log files were missing for a few hours. The CloudTrail console shows that trails are enabled in all accounts. The central-bucket has default encryption enabled. What is the MOST likely cause of the missing logs?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The S3 bucket policy denies access unless the PutObject request includes the x-amz-server-side-encryption header with value AES256
The bucket policy denies PutObject requests that do not include the `x-amz-server-side-encryption` header with value `AES256`. CloudTrail does not include this header by default when delivering logs, so the requests are denied, causing missing logs. The bucket's default encryption (SSE-S3) does not override the bucket policy requirement. Option D is correct because it directly addresses the policy condition that blocks CloudTrail writes. Options A, B, and C are incorrect: A refers to multi-region trails, but the issue is about encryption headers; B is wrong because CloudTrail uses HTTPS, not HTTP; C is wrong because the IAM role permissions are not the issue—the bucket policy is the cause.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The CloudTrail trail is not configured to deliver to the central bucket from all regions
Why it's wrong here
This cannot be the cause because the question explicitly states trails are enabled in all accounts, and a missing regional configuration would produce a consistent absence of logs from that region, not an intermittent gap of a few hours. Organization trails automatically capture all regions, and even individual account trails can be set to deliver globally. If a region were excluded, the logs would simply never appear, rather than appear sporadically, so the intermittent pattern points to a temporary access-denied issue, not a configuration omission.
- ✗
The S3 bucket policy contains a deny condition that requires aws:SecureTransport to be true, but CloudTrail uses HTTP
Why it's wrong here
This fails because CloudTrail always communicates with Amazon S3 over HTTPS/TLS, so a bucket policy condition requiring `aws:SecureTransport: true` is automatically satisfied by every legitimate CloudTrail delivery. CloudTrail does not use plain HTTP, and a denial based on transport would be permanent and total, not limited to a few hours. Moreover, requiring SecureTransport is a common security best practice precisely because services like CloudTrail and S3 use TLS, making this condition harmless rather than disruptive.
- ✗
The IAM role used by CloudTrail does not have s3:PutObject permission
Why it's wrong here
If the IAM role used by CloudTrail lacked `s3:PutObject`, CloudTrail would fail to deliver log files from the very first attempt, producing a permanent and complete absence of logs rather than a short intermittent gap. The role is a static permission assignment; either it has the permission or it does not, and the resulting behavior would be deterministic. Since the question reports missing logs only for a few hours, the failure is more likely caused by a conditional bucket policy that intermittently rejects requests, not by a missing role permission.
- ✓
The S3 bucket policy denies access unless the PutObject request includes the x-amz-server-side-encryption header with value AES256
Why this is correct
This is the correct explanation: the S3 bucket policy includes a condition that requires the `x-amz-server-side-encryption` header to be present with a value of `AES256` on every PutObject request. CloudTrail, when delivering log files to S3, does not automatically include that header in its API call; it relies on the bucket's default encryption policy instead. As a result, CloudTrail's PutObject requests fail the policy condition and are denied, causing the log delivery gap. The intermittent nature could be due to CloudTrail's retry logic or the recent introduction of the policy condition, but the root cause is the header mismatch between the bucket policy and CloudTrail's request format.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.