Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company has multiple AWS accounts and wants to centrally aggregate VPC Flow Logs from all accounts into a single S3 bucket in the logging account. What is the MOST secure way to configure cross-account delivery?

⚠ Common exam trap

The trap here is that candidates may overcomplicate the solution by choosing a streaming service like Kinesis Firehose or misapply CloudTrail, not realizing that VPC Flow Logs have a native cross-account S3 delivery capability that is both secure and simple.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create VPC Flow Logs in each account, specifying the central S3 bucket ARN as the destination, and configure the bucket policy to allow the flow logs service principal to write.

VPC Flow Logs can be published directly to an S3 bucket in another account by specifying the bucket ARN as the destination. The logging account's bucket policy must grant the `s3:PutObject` permission to the VPC Flow Logs service principal (`delivery.logs.amazonaws.com`) for the cross-account write to succeed. This approach avoids sharing credentials or introducing additional services, maintaining a secure and direct delivery path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudTrail to log flow logs and deliver to the central bucket.

    Why it's wrong here

    CloudTrail records API activity, such as who called ec2.CreateVpc or s3.PutObject, and can deliver log files to a centralized S3 bucket via a trail. However, CloudTrail does not capture network packets or VPC traffic metadata, which is the domain of VPC Flow Logs. Creating a trail would not generate or forward flow logs; you would still need to separately enable VPC Flow Logs, making this an incomplete and incorrect solution for the stated requirement.

  • ✓

    Create VPC Flow Logs in each account, specifying the central S3 bucket ARN as the destination, and configure the bucket policy to allow the flow logs service principal to write.

    Why this is correct

    For each member account, you enable VPC Flow Logs and set the destination to the central S3 bucket's ARN (e.g., arn:aws:s3:::central-bucket/flowlogs). The central account must attach a bucket policy that grants s3:PutObject to the VPC Flow Logs service principal, typically vpc-flow-logs.amazonaws.com, with a resource condition that limits writes to the source account's AWSLogs prefix. Once configured, flow records are published directly and continuously from each account to the central bucket without any additional credentials or infrastructure, making this the native and correct cross-account delivery mechanism.

  • ✗

    Share the central bucket's access key with each account to write directly.

    Why it's wrong here

    An S3 bucket itself does not possess an access key; to use this approach you would have to create an IAM user in the central account and distribute that user's long-term access keys to every member account. Storing shared static secrets across multiple accounts is a security anti-pattern, violates the principle of least privilege, and makes key rotation painful. More fundamentally, VPC Flow Logs does not accept user-supplied AWS credentials for S3 destinations; it authenticates as the flow logs service, so this option could not even be implemented technically.

  • ✗

    Use Amazon Kinesis Data Firehose to stream flow logs from each account to the central S3 bucket.

    Why it's wrong here

    Kinesis Data Firehose is a managed streaming ingestion service that can deliver data to S3, but VPC Flow Logs does not list Firehose as a destination — supported targets are CloudWatch Logs and S3 directly. To use Firehose you would need an intermediate glue (e.g., a subscription filter from CloudWatch Logs to Lambda that then puts records into Firehose), which adds complexity, latency, and cost. Because direct S3 delivery is already available, introducing Firehose is an unnecessary detour and not a valid native cross-account flow log delivery solution.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.