DOP-C02 Incident and Event Response Practice Question
A company uses CloudWatch Logs to store application logs. The security team requires that logs be encrypted at rest using a customer-managed KMS key. What must be done to enable this?
⚠ Common exam trap
A common mix-up: candidates assume encryption is automatically applied when a KMS key exists in the account, but they overlook the critical step of updating the key policy to grant CloudWatch Logs service principal permissions to use the key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Associate a customer-managed KMS key with the log group and update the key policy to allow CloudWatch Logs to use it.
CloudWatch Logs supports encryption at rest using a customer-managed KMS key. To enable this, you must associate the KMS key with the log group via the CloudWatch Logs console or API, and you must update the key policy to grant CloudWatch Logs the necessary permissions (kms:Encrypt, kms:Decrypt, kms:ReEncrypt*, kms:GenerateDataKey*, and kms:DescribeKey). Without this key policy update, CloudWatch Logs cannot use the key to encrypt the log data at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable encryption on the log group using the default AWS managed key.
Why it's wrong here
The default encryption for CloudWatch Logs uses AWS-owned keys rather than a customer-managed key, so selecting the default AWS managed key would not meet a requirement to control your own encryption keys. CloudWatch Logs does not let you explicitly enable encryption with the default AWS managed key; you can only associate a customer-managed KMS key with a log group, and the default encryption is already applied automatically.
- ✗
Use a third-party encryption tool before sending logs to CloudWatch.
Why it's wrong here
While a third-party encryption tool could encrypt log payloads before they are sent, CloudWatch Logs already natively supports server-side encryption with AWS KMS, so this extra layer would be unnecessary and would prevent CloudWatch Logs Insights from querying the plaintext log events. The correct approach is to use KMS encryption on the log group itself, which is transparent and does not alter the log data format.
- ✗
Create a new log group in a region where KMS is enabled.
Why it's wrong here
Creating a new log group in a different region does not solve the encryption requirement because AWS KMS is available in every AWS region and log group encryption is configured per log group, not per region. The original log group still needs to be associated with a customer-managed KMS key, or the log data must be moved to a new log group and then encrypted with the appropriate key policy.
- ✓
Associate a customer-managed KMS key with the log group and update the key policy to allow CloudWatch Logs to use it.
Why this is correct
To encrypt a CloudWatch Logs log group with a customer-managed KMS key, you must create or select a KMS key, update its key policy to grant the CloudWatch Logs service principal permissions such as kms:Encrypt, kms:Decrypt, kms:GenerateDataKey*, and kms:DescribeKey, and then associate that key with the log group using the console or the associate-kms-key API. This server-side encryption protects log data at rest and allows CloudWatch Logs to decrypt the data internally for features like log queries.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.