Enabling S3 Data Events in CloudTrail Across an Organization
A company has a CloudTrail trail that logs management events for all regions. The security team notices that some S3 data events are not being logged. How should the team enable logging for all S3 data events?
⚠ Common exam trap
Many exam-takers think S3 server access logging (Option D) is equivalent to CloudTrail data events, but server access logs are separate, bucket-specific logs that lack the centralized management, API-level detail, and integration with CloudTrail Insights or other monitoring services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the existing CloudTrail trail to include data events for S3
CloudTrail trails can be configured to log data events for S3 in addition to management events. By updating the existing trail to include S3 data events (e.g., GetObject, PutObject), the security team can capture all object-level API activity without creating a separate trail. This ensures comprehensive logging while maintaining the existing management event logging for all regions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Update the existing CloudTrail trail to include data events for S3
Why this is correct
CloudTrail trails can be updated at any time to include data events for specific S3 buckets or all buckets, capturing object-level operations such as GetObject, PutObject, and DeleteObject in addition to the existing management events. This consolidates all API activity into a single audit stream, avoids the operational overhead of managing multiple trails, and is the direct, recommended way to meet the requirement for S3 access logging within CloudTrail.
- ✗
Create a new CloudTrail trail that logs only data events
Why it's wrong here
Creating a new CloudTrail trail solely for data events would fragment your audit logs across multiple destinations, forcing you to search separate S3 buckets or CloudWatch Logs groups for object-level activity. Additionally, any new trail can be configured to log both management and data events, so you would either duplicate management event logging or be forced to disable management events, increasing complexity and cost without adding value over simply updating the existing trail.
- ✗
Use Amazon GuardDuty to monitor S3 access
Why it's wrong here
Amazon GuardDuty is a threat detection service that consumes CloudTrail management events, VPC flow logs, and DNS logs to generate security findings; it does not itself log S3 object-level access. Without CloudTrail data events enabled, GuardDuty lacks the underlying activity data to identify suspicious S3 API calls, and it never provides a durable, queryable audit history for compliance or forensics, making it unsuitable for this logging requirement.
- ✗
Enable S3 server access logging on each bucket
Why it's wrong here
S3 server access logging produces a separate, bucket-local log of requests to that bucket, but it is entirely distinct from CloudTrail and does not integrate with your existing management event trail. Server access logs are written to a destination bucket, have a different log format (including fields like request ID and operation), and must be enabled and managed per bucket, whereas the requirement is for a unified audit trail via CloudTrail; enabling data events in the existing trail achieves that without the overhead of per-bucket server access logs.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.