DOP-C02 Security and Compliance Practice Question
A company wants to enable AWS CloudTrail to log all API calls across multiple accounts in AWS Organizations. The security team requires that logs be encrypted at rest and that any unauthorized deletion of log files be prevented. Which TWO actions should the security team take? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a trail in the management account that applies to all accounts in the organization.
Enabling CloudTrail for all accounts in the organization ensures centralized logging. Option D is correct because S3 Object Lock prevents deletion of log files. Option B is incorrect because KMS with a customer managed key provides encryption, but the key must be created beforehand, not just enabled. Option C is incorrect because CloudWatch Logs encryption uses KMS, not S3 SSE. Option E is incorrect because CloudTrail can be configured to log management events by default, and this is not about data events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a trail in the management account that applies to all accounts in the organization.
Why this is correct
By creating an organization trail in the management account (using AWS Organizations), CloudTrail automatically logs API activity for all member accounts, including the management account itself, without needing to configure trails in each account. This centralizes governance and ensures the requirement of logging all API calls across the entire AWS environment is met, as organization trails deliver log files for every account to a single S3 bucket.
- ✗
Enable default encryption with SSE-S3 on the S3 bucket where CloudTrail delivers logs.
Why it's wrong here
SSE-S3 provides encryption at rest for the log files, but it is the default encryption mechanism that AWS manages the keys for, and it does not provide the ability to control or audit key usage. The requirement is likely about preventing deletion or ensuring logging completeness, not just encryption; SSE-S3 does not address log file immutability or deletion prevention. Even if enabled, it does not prevent unauthorized deletion of log files, as S3 Object Lock or bucket policies would be needed. Therefore, this option is relevant to encryption but not to the primary requirement of logging all API calls across all accounts.
- ✗
Configure CloudTrail to send logs to Amazon CloudWatch Logs and enable encryption using an AWS KMS key.
Why it's wrong here
While sending CloudTrail logs to CloudWatch Logs enables real-time monitoring and using a KMS key encrypts those logs, this configuration neither captures API calls from all accounts nor safeguards the original S3 log files from deletion. CloudTrail still delivers to an S3 bucket; CloudWatch Logs is just an additional destination, and encryption in CloudWatch does not establish a retention policy or immutable storage. The requirement is to log all API calls organization-wide, which requires an organization trail, not just a CloudWatch Logs integration.
- ✓
Enable S3 Object Lock on the destination S3 bucket to prevent log file deletion.
Why this is correct
S3 Object Lock in compliance or governance mode applies a retention period to the CloudTrail log objects, making them immutable and preventing any user (including the root account) from deleting or overwriting them until the retention expires. This satisfies the requirement to prevent deletion of log files, ensuring a tamper-proof audit trail. Since CloudTrail delivers logs to S3, configuring Object Lock on the destination bucket is a critical security control for log integrity. Note that Object Lock must be enabled when the bucket is created, and it works alongside the organization trail to provide both comprehensive logging and deletion protection.
- ✗
Enable CloudTrail Insights to detect unusual API activity.
Why it's wrong here
CloudTrail Insights is an optional feature that uses machine learning to identify unusual API activity and error rates, providing anomaly detection for security monitoring. It does not change the scope of what is logged (all accounts are already logged if an organization trail is configured) nor does it prevent deletion of log files or add encryption. Insights merely adds a separate set of insights events; it does not address the requirement of logging all API calls or preserving those logs. Thus enabling Insights is a supplementary monitoring capability, not a solution to the stated requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.