SAP-C02 Continuous Improvement for Existing Solutions Practice Question
A company is using AWS CloudTrail to log API activity. The security team wants to ensure that log files are tamper-proof and can be used for forensic analysis. Which TWO actions should the company take?
⚠ Common exam trap
SAP-C02 often tests the misconception that encryption (SSE-KMS) equals tamper-proofing — candidates pick encryption when the question actually demands integrity and immutability controls like Object Lock and log file validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable S3 Object Lock on the CloudTrail S3 bucket.
Option A is correct because enabling S3 Object Lock on the CloudTrail S3 bucket (in compliance or governance mode with a retention period) uses WORM (write-once-read-many) semantics to prevent log files from being deleted or overwritten, which is essential for tamper-proof forensic evidence. Option B is correct because CloudTrail log file validation generates a digitally signed digest file for each log, allowing you to verify via the AWS CLI (aws cloudtrail validate-logs) that logs have not been altered or deleted after delivery. Option C is not correct here because SSE-KMS provides encryption at rest and access control but does not by itself prevent tampering or deletion of log files. Option D is not correct because S3 Transfer Acceleration only speeds up uploads over long distances and has no bearing on log integrity. Option E is not correct because a Lifecycle policy transitioning logs to S3 Glacier changes storage class and could affect availability, but it does not make logs tamper-proof.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable S3 Object Lock on the CloudTrail S3 bucket.
Why this is correct
S3 Object Lock enforces WORM protection at the object level, preventing deletion or modification of CloudTrail log files for a defined retention period. This directly satisfies the tamper-proof requirement, preserving log integrity so the files remain admissible for forensic analysis even if credentials are compromised.
- ✓
Enable CloudTrail log file validation.
Why this is correct
CloudTrail log file validation generates a digest file for each delivered log, letting you verify that logs were not altered or deleted after delivery. This directly satisfies the tamper-proof and forensic integrity requirement, since any modification breaks the digest chain and is detectable during investigation.
- ✗
Use server-side encryption with AWS KMS managed keys (SSE-KMS).
Why it's wrong here
SSE-KMS encrypts log objects at rest but does not prevent deletion or alteration; a principal with bucket permissions can still overwrite or remove files, so tamper-evidence is absent. It is tempting because encryption protects confidentiality, yet forensic integrity requires validation, delivered by CloudTrail log file integrity validation with digest files.
- ✗
Enable S3 Transfer Acceleration on the CloudTrail S3 bucket.
Why it's wrong here
Transfer Acceleration only speeds uploads to S3 over long distances; it adds no integrity or immutability control, so log files remain alterable. It is tempting because it is an S3 bucket-level feature that sounds protective, but the requirement is tamper-proof forensic evidence, met by log file integrity validation and restrictive bucket policies.
- ✗
Set an S3 Lifecycle policy to transition logs to Amazon S3 Glacier.
Why it's wrong here
Lifecycle transition to S3 Glacier changes storage class and cost, not immutability; objects can still be deleted or overwritten before transition, and Glacier vault locks are not applied. It is tempting because archival implies long-term retention, but forensic tamper-proofing needs integrity validation plus S3 Object Lock or restrictive policies.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.