Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company has a serverless application using AWS Lambda, API Gateway, and DynamoDB. The security team wants to detect and respond to potential SQL injection attempts in API requests. They have enabled AWS WAF on the API Gateway and created a rule to block SQL injection. However, they also want to capture the blocked requests for analysis and store them in an S3 bucket. The team has configured WAF to send logs to Amazon Kinesis Data Firehose, which delivers to an S3 bucket. After testing, the team notices that the logs are not being delivered. The Firehose delivery stream is in the same AWS account, and the S3 bucket policy allows the Firehose service to write. What is the most likely cause?

⚠ Common exam trap

The trap is assuming that an S3 bucket policy alone is sufficient for Firehose to write. Candidates often overlook the need for an IAM role that Firehose assumes to access the bucket, leading them to choose option C instead of B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Kinesis Data Firehose delivery stream does not have an IAM role with permissions to write to the S3 bucket.

The most likely cause is that the Kinesis Data Firehose delivery stream lacks an IAM role with permissions to write to the S3 bucket. Even if the S3 bucket policy allows the Firehose service to write, Firehose assumes an IAM role to access the bucket. If that role does not have the necessary permissions (e.g., s3:PutObject), delivery fails. The other options are less likely because WAF logging is configured (since logs are attempted), the S3 bucket policy is stated to allow write, and Firehose buffering is normal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The WAF web ACL is not configured to log blocked requests.

    Why it's wrong here

    WAF logging can be configured to record either all requests or only those that match specific rules, but the logs are always sent to a Kinesis Data Firehose delivery stream, not directly to an S3 bucket. If the delivery stream's IAM role lacks s3:PutObject permissions, the Firehose delivery will fail before any data reaches S3, regardless of whether the web ACL is set to log blocked requests. Therefore, failing to log only blocked requests would not prevent allowed requests from appearing in the bucket, and it is not the cause of the missing logs.

  • ✓

    The Kinesis Data Firehose delivery stream does not have an IAM role with permissions to write to the S3 bucket.

    Why this is correct

    The Kinesis Data Firehose delivery stream is configured with an IAM role that it assumes to write to the destination S3 bucket. If that role does not have a permissions policy allowing s3:PutObject (and s3:GetBucketLocation) on the target bucket, Firehose attempts to deliver records but receives an AccessDenied error from S3. The delivery stream may still accept records from WAF, but the data is never written to the bucket, leaving the bucket empty. This is the most direct explanation for logs being absent, because the Firehose-to-S3 step is where the chain fails.

  • ✗

    The S3 bucket policy does not grant write permissions to the Firehose delivery stream's IAM role.

    Why it's wrong here

    Firehose does not use the S3 bucket policy as its primary authorization mechanism for writes; it operates by assuming an IAM role that is associated with the delivery stream. Even if the bucket policy includes a grant to the Firehose service principal (firehose.amazonaws.com), S3 requests made by Firehose are signed with the assumed role's credentials, not the service principal. Thus, a bucket policy that does not explicitly grant write permissions to the delivery stream role is not the underlying issue—the missing s3:PutObject on the role itself is. An explicit bucket policy could even be unnecessary if the role's permissions allow S3 writes on that bucket.

  • ✗

    Kinesis Data Firehose delivers logs in batches every 5 minutes, so the team should wait longer.

    Why it's wrong here

    Kinesis Data Firehose introduces buffering, with a maximum buffer interval of 300 seconds (5 minutes) and a buffer size that varies by destination, but it is designed to deliver records in near real time once those thresholds are met. If the WAF web ACL is actively sending logs, Firehose would flush buffered records to S3 within a few minutes, so waiting longer would not explain an S3 bucket that remains empty for an extended period. Additionally, if the delivery stream is failing on permissions, Firehose does not retry indefinitely; it logs the failure and eventually drops the records. The absence of logs after a reasonable interval strongly points to a configuration issue like IAM, not batching latency.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.