Courseiva
Data Protection →mediumMultiple Select

SCS-C02 Data Protection Practice Question

A company is designing a data protection strategy for its Amazon S3 bucket that stores sensitive documents. The security team requires that all data be encrypted in transit and at rest, and that any accidental deletion of objects can be reversed within 30 days. Additionally, the company must be able to audit all access attempts to the bucket, including failed attempts. Which TWO actions should the company take to meet these requirements? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse S3 server access logs (which log successful requests only) with CloudTrail data events (which log all API calls, including failures), leading them to select Option D instead of Option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail with data events for S3.

AWS CloudTrail with data events for S3 is correct because it captures all S3 API calls, including GetObject, PutObject, and DeleteObject, and records both successful and failed access attempts. This meets the auditing requirement for all access attempts, including failed ones, as CloudTrail logs the request details, error codes, and source IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default encryption on the bucket using SSE-S3.

    Why it's wrong here

    Default encryption with SSE-S3 encrypts objects at rest using an Amazon-managed AES-256 key, but it does not protect data in transit; you must also enforce TLS/HTTPS for uploads and downloads. Encryption addresses confidentiality only—it has no effect on preservation, deletion recovery, or access auditing. Therefore, SSE-S3 alone cannot satisfy a data protection strategy that requires retention and forensic visibility.

  • ✓

    Enable AWS CloudTrail with data events for S3.

    Why this is correct

    Enabling CloudTrail with data events for an S3 bucket records object-level operations such as GetObject, PutObject, DeleteObject, and HeadObject, capturing the IAM principal, source IP, and whether the request succeeded or failed. This creates an authoritative, queryable audit trail that can be searched in CloudTrail Lake or Athena and is essential for incident investigation, compliance reporting, and detecting compromised credentials. Unlike server access logs, CloudTrail data events reliably include failed attempts.

  • ✓

    Enable S3 Versioning on the bucket.

    Why this is correct

    Versioning causes every PutObject to create a new version rather than overwrite, and a DeleteObject operation inserts a delete marker while retaining all prior versions. If the marker is removed, the original object returns, enabling recovery after accidental deletion, ransomware overwrites, or application errors. This is the primary recovery control because it preserves data itself; however, lifecycle rules may permanently delete old versions, so expiration policies must match your recovery point objectives.

  • ✗

    Enable S3 server access logs and send them to a separate bucket.

    Why it's wrong here

    S3 server access logs are delivered on a best-effort basis to a destination bucket and can be subject to delay, incompleteness, and missing entries for denied requests, making them unreliable for security forensics. They also require a separate logging bucket and careful lifecycle management to avoid unbounded log growth. For audit-grade trails, CloudTrail data events are preferred because they log all API calls deterministically, including failures.

  • ✗

    Enable MFA Delete on the bucket.

    Why it's wrong here

    MFA Delete protects against unauthorized permanent deletion by requiring a one-time authentication code for destructive versioning operations, such as permanently deleting a version or suspending versioning. However, it is not a recovery mechanism—if an object was deleted before versioning was enabled, or if MFA validation succeeds for an authorized action, that deletion cannot be undone by MFA Delete. Versioning is what provides the retained copies that make recovery possible; MFA Delete only adds a stronger permissions barrier.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.