Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company is using AWS CloudTrail to log API calls and wants to ensure that log files are not tampered with after delivery to S3. Which feature should be enabled to validate the integrity of CloudTrail log files?

⚠ Common exam trap

Many candidates confuse data integrity validation with data protection features like encryption or versioning, mistakenly thinking that preventing deletion or encrypting data also ensures the data hasn't been tampered with.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable CloudTrail log file validation

Enabling CloudTrail log file validation creates a digest file for each log file delivery, which includes a SHA-256 hash of the log file. This digest is signed using the private key of a dedicated CloudTrail key pair, allowing you to verify the integrity and authenticity of the log files by comparing the hash against the digest, ensuring no tampering occurred after delivery to S3.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable CloudTrail log file validation

    Why this is correct

    CloudTrail log file validation creates a SHA-256 hash of each log file and stores it in a digest file in the same S3 bucket. When enabled, you can use the AWS CLI or API to validate that log files were not modified or deleted after delivery. It uses a private key to sign the digest files, providing cryptographic assurance that the logs themselves are authentic and intact. This directly detects any tampering with log integrity, unlike the other options.

  • ✗

    Enable MFA Delete on the S3 bucket

    Why it's wrong here

    MFA Delete requires a multi-factor authentication token to permanently delete an object version or suspend versioning on the bucket. While this helps protect against accidental or unauthorized deletion of CloudTrail logs, it does not verify whether the log file contents have been modified after being written. MFA Delete is a deletion control, not an integrity control, so it cannot detect tampering or prove that logs retain their original state.

  • ✗

    Enable S3 Versioning on the bucket

    Why it's wrong here

    S3 Versioning preserves every version of an object, allowing you to restore a previous version if a log is overwritten or deleted. It provides availability and recovery capabilities but does not compute any hashes or signatures to validate that a log file's content has not been altered. An attacker with permissions could modify a log file and versioning would simply create a new version without flagging the change. Thus, versioning alone cannot ensure the authenticity or integrity of CloudTrail logs.

  • ✗

    Enable S3 bucket default encryption

    Why it's wrong here

    Default encryption for the S3 bucket ensures that CloudTrail log files are encrypted at rest using SSE-S3 or SSE-KMS. Encryption protects the confidentiality of the log data by preventing unauthorized parties from reading it, but it does not detect whether the ciphertext or plaintext has been tampered with. Integrity validation requires cryptographic hashing or digital signatures, not encryption. Therefore, default encryption does not help verify that the logs have not been modified.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.