Courseiva
Incident ResponsehardMultiple ChoiceObjective-mapped

SCS-C03 Incident Response Practice Question

An organization is preparing for a potential incident and wants to ensure that responders can quickly access logs across multiple accounts. Which architecture is recommended for centralized log management?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Aggregate logs into a dedicated, centralized security account.

Creating a dedicated, separate Log Archive account is the industry standard for centralized log management. By aggregating CloudTrail and other logs into a single, hardened account with restricted access, the organization ensures that even if a production account is fully compromised, the audit trail remains secure and available for forensic investigation. This architecture prevents an attacker from destroying the evidence of their actions within the production environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Store logs locally in each account within a private S3 bucket.

    Why it's wrong here

    Storing logs locally leaves them vulnerable to deletion or tampering if the account is compromised. It also makes incident response slow and cumbersome, as responders must manually aggregate data from every single account individually, which is inefficient during a critical security event that requires rapid analysis.

  • Aggregate logs into a dedicated, centralized security account.

    Why this is correct

    Centralizing logs into a dedicated account provides an immutable and secure audit trail. By separating the log storage from the production environment, the organization ensures that logs are protected even if an attacker gains administrative privileges within a production account, facilitating faster and more reliable incident investigations.

  • Enable CloudTrail logs to be sent directly to an on-premises SIEM.

    Why it's wrong here

    While shipping logs to a SIEM is a good practice, it does not replace the need for an S3-based log archive. If the network connection is interrupted or if there's a delay in SIEM processing, the original logs in S3 are the source of truth that must be preserved.

  • Use CloudWatch Logs to stream all data to an Amazon OpenSearch cluster.

    Why it's wrong here

    Streaming to OpenSearch is excellent for real-time analysis, but it does not satisfy the long-term storage and integrity requirements of an audit trail. A dedicated, durable S3-based log archive is necessary to ensure evidence is preserved for long-term forensic use and regulatory compliance requirements in incident response.

About these practice questions

This SCS-C03 question is part of Courseiva's 99-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.