SCS-C02 Security Logging and Monitoring Practice Question
A company is using AWS CloudTrail to log API calls and wants to ensure that log files are not tampered with after delivery to S3. Which feature should be enabled to validate the integrity of CloudTrail log files?
⚠ Common exam trap
Many candidates confuse data integrity validation with data protection features like encryption or versioning, mistakenly thinking that preventing deletion or encrypting data also ensures the data hasn't been tampered with.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable CloudTrail log file validation
Enabling CloudTrail log file validation creates a digest file for each log file delivery, which includes a SHA-256 hash of the log file. This digest is signed using the private key of a dedicated CloudTrail key pair, allowing you to verify the integrity and authenticity of the log files by comparing the hash against the digest, ensuring no tampering occurred after delivery to S3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable CloudTrail log file validation
Why this is correct
CloudTrail log file validation creates a SHA-256 hash of each log file and stores it in a digest file in the same S3 bucket. When enabled, you can use the AWS CLI or API to validate that log files were not modified or deleted after delivery. It uses a private key to sign the digest files, providing cryptographic assurance that the logs themselves are authentic and intact. This directly detects any tampering with log integrity, unlike the other options.
- ✗
Enable MFA Delete on the S3 bucket
Why it's wrong here
MFA Delete requires a multi-factor authentication token to permanently delete an object version or suspend versioning on the bucket. While this helps protect against accidental or unauthorized deletion of CloudTrail logs, it does not verify whether the log file contents have been modified after being written. MFA Delete is a deletion control, not an integrity control, so it cannot detect tampering or prove that logs retain their original state.
- ✗
Enable S3 Versioning on the bucket
Why it's wrong here
S3 Versioning preserves every version of an object, allowing you to restore a previous version if a log is overwritten or deleted. It provides availability and recovery capabilities but does not compute any hashes or signatures to validate that a log file's content has not been altered. An attacker with permissions could modify a log file and versioning would simply create a new version without flagging the change. Thus, versioning alone cannot ensure the authenticity or integrity of CloudTrail logs.
- ✗
Enable S3 bucket default encryption
Why it's wrong here
Default encryption for the S3 bucket ensures that CloudTrail log files are encrypted at rest using SSE-S3 or SSE-KMS. Encryption protects the confidentiality of the log data by preventing unauthorized parties from reading it, but it does not detect whether the ciphertext or plaintext has been tampered with. Integrity validation requires cryptographic hashing or digital signatures, not encryption. Therefore, default encryption does not help verify that the logs have not been modified.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.