Courseiva
Security and Compliance →easyMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company wants to centralize audit logs from multiple AWS accounts into a single S3 bucket. The logs must be encrypted at rest using a KMS key. Which solution is the MOST secure and scalable?

⚠ Common exam trap

The trap is overcomplicating the solution with streaming services (Kinesis) or manual copying — candidates often overlook the native, scalable CloudTrail-to-S3 cross-account pattern that AWS explicitly supports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure each account's CloudTrail to send logs to a central S3 bucket with a bucket policy that grants cross-account permissions

Configuring each account's CloudTrail to deliver logs directly to a central S3 bucket with a bucket policy granting cross-account permissions is the most secure and scalable solution. It uses native AWS service integration, avoids custom code, and supports KMS encryption at rest. The bucket policy enforces least privilege and can require SSE-KMS with a specific key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an IAM role in each account and manually copy logs to a central bucket

    Why it's wrong here

    Manually copying CloudTrail logs via IAM roles is not a scalable or reliable pattern: it requires custom scripts or human intervention, lacks automation for continuous delivery, and risks incomplete or stale logs. IAM roles grant permissions but do not perform data movement. This approach also bypasses CloudTrail's native S3 delivery mechanism, making it error-prone and difficult to audit.

  • ✓

    Configure each account's CloudTrail to send logs to a central S3 bucket with a bucket policy that grants cross-account permissions

    Why this is correct

    This is the standard pattern: configure CloudTrail in each AWS account (or use an organization trail) to deliver log files directly to a central S3 bucket, and attach a bucket policy that grants the CloudTrail service principal from each source account permission to write objects (s3:PutObject, s3:GetBucketAcl). This approach is fully automated, idempotent, and preserves log integrity. For additional security, you can enable SSE-KMS, but the KMS key policy must also allow the CloudTrail service for each account.

  • ✗

    Use Amazon Kinesis Data Firehose to stream logs to S3

    Why it's wrong here

    Kinesis Data Firehose is not the most direct or native mechanism for centralising AWS CloudTrail audit logs from multiple accounts to S3. CloudTrail can be configured to deliver logs directly to a central S3 bucket, making Firehose an unnecessary intermediary for this specific use case. However, it is a highly scalable solution for streaming other types of data, such as application logs or IoT data, from various sources to S3, handling buffering, compression, and encryption automatically.

  • ✗

    Use AWS Config rules to aggregate logs into a central bucket

    Why it's wrong here

    AWS Config rules are an evaluation engine that checks resource configurations against desired policies and can trigger remediation actions, but they have no native mechanism to transport or aggregate CloudTrail log files. Config's own aggregation feature only consolidates configuration items, not CloudTrail logs. While you could theoretically use a Config rule with a Lambda function to copy logs, that is an indirect, non-standard hack that violates the intended use of Config and introduces unnecessary complexity.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.