SCS-C02 Security Logging and Monitoring Practice Question
A company is using Amazon CloudWatch Logs to collect logs from its EC2 instances. The security team wants to ensure that logs are encrypted at rest and that access to the logs is controlled. Which solution should the team implement?
⚠ Common exam trap
Candidates often confuse S3 encryption options (SSE-S3, SSE-C) with CloudWatch Logs encryption, or assume that S3 bucket policies can be applied to CloudWatch Logs, when in fact CloudWatch Logs uses KMS for encryption and IAM for access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption using AWS KMS customer managed keys (CMK) and apply IAM policies to control access.
CloudWatch Logs supports encryption at rest using AWS KMS customer managed keys (CMK), which allows the security team to control access to the encrypted log data via IAM policies and key policies. This ensures both encryption and fine-grained access control, meeting the requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable encryption using AWS KMS customer managed keys (CMK) and apply IAM policies to control access.
Why this is correct
CloudWatch Logs supports server-side encryption with customer-managed KMS keys (CMKs). When you associate a CMK with a log group, the service uses envelope encryption: it calls KMS to generate a data key that encrypts your log data, and that data key is then encrypted by the CMK. To control access, you must configure both the KMS key policy and IAM policies that grant or deny actions such as kms:Decrypt and logs:DescribeLogGroups. This is the only method natively supported by CloudWatch Logs for customer-controlled encryption keys.
- ✗
Use SSE-C with a customer-provided key to encrypt log data.
Why it's wrong here
SSE-C is an Amazon S3 server-side encryption feature where you supply your own raw encryption key with each request. CloudWatch Logs does not accept customer-provided keys per API call and does not implement the SSE-C protocol. The service instead relies on AWS KMS for server-side encryption of log groups, so attempting to use SSE-C for CloudWatch Logs would not work and is not a valid configuration.
- ✗
Use SSE-S3 to encrypt the log data in CloudWatch Logs.
Why it's wrong here
SSE-S3 is specifically an Amazon S3 encryption mode that uses S3-managed keys (Amazon S3 uses AWS-managed keys to encrypt objects). CloudWatch Logs is a separate managed service, not a bucket, and its log data is not stored as S3 objects. While exported log data to S3 can be encrypted with SSE-S3, that does not encrypt log data at rest within CloudWatch Logs itself, so this option is inapplicable.
- ✗
Enable default encryption on the log group and use S3 bucket policies.
Why it's wrong here
CloudWatch Logs has a default encryption option that uses AWS-managed KMS keys (aws/logs), not customer-managed keys, and it is not called 'default encryption' in the way you would configure an S3 bucket. S3 bucket policies are irrelevant here because CloudWatch Logs is not an S3 resource and does not evaluate S3 bucket policies for access control. To restrict access to log groups, you must use IAM policies that include actions like logs:CreateLogGroup and logs:DescribeLogStreams, not S3 bucket policies.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.