SCS-C02 Infrastructure Security Practice Question
A company is using AWS CloudTrail to log API calls. The security team wants to ensure that the logs are protected from unauthorized access and deletion. Which TWO actions should be taken?
⚠ Common exam trap
Test-takers frequently confuse 'protecting logs from deletion' with 'preventing deletion' and incorrectly choose S3 Versioning (Option D) as a security control, when in fact versioning only helps recover from accidental deletion, not prevent malicious deletion by an authorized user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable server-side encryption using AWS KMS (SSE-KMS) on the S3 bucket.
Enabling server-side encryption using AWS KMS (SSE-KMS) on the S3 bucket that stores CloudTrail logs ensures that the log files are encrypted at rest, protecting them from unauthorized access. This encryption uses envelope encryption with a customer-managed or AWS-managed KMS key, providing an additional layer of access control via KMS key policies and IAM policies. Option C is correct because CloudTrail log file validation creates a signed digest file for each log file, allowing you to verify that the logs have not been tampered with, deleted, or modified after delivery. This uses SHA-256 hashing and digital signing with the private key of AWS, ensuring integrity and authenticity of the log files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable server-side encryption using AWS KMS (SSE-KMS) on the S3 bucket.
Why this is correct
Server-side encryption with AWS KMS (SSE-KMS) encrypts CloudTrail log objects at rest using envelope encryption with a customer-managed CMK, ensuring that the API activity data is unreadable to unauthorized parties. CloudTrail integrates natively with SSE-KMS, and you can configure the bucket to use a KMS key for all delivered logs, which also provides an additional layer of protection for sensitive information such as user credentials or IP addresses. This is the correct choice because it directly addresses the confidentiality of the logs, a fundamental security requirement.
- ✗
Use S3 bucket ACLs to restrict access.
Why it's wrong here
Using S3 bucket ACLs to restrict access is not a reliable security control because ACLs are a legacy mechanism with limited granularity and are often overridden by bucket policies, which are the recommended way to manage cross-account access. For CloudTrail logs, you should use a bucket policy to explicitly grant write access to CloudTrail and restrict read access to only the required IAM principals. Relying on ACLs can lead to misconfigurations or conflicts with the bucket policy, potentially exposing the logs unintentionally.
- ✓
Enable CloudTrail log file validation.
Why this is correct
Enabling CloudTrail log file validation creates a SHA-256 hash for each log file and digitally signs it with a private key from CloudTrail, allowing you to verify that the logs were not modified, deleted, or tampered with after delivery. This integrity check is an important security measure for forensic analysis and ensures that the recorded API calls are trustworthy. It works by generating a digest file that you can inspect to confirm the authenticity of each log file, making it a correct and recommended safeguard.
- ✗
Enable S3 Versioning on the bucket.
Why it's wrong here
Enabling S3 Versioning on the bucket preserves every version of an object, including overwritten or deleted log files, which helps you recover data in the event of accidental deletion or overwrites. However, versioning does not prevent an authorized user with the appropriate permissions from permanently deleting versions or from reading the log contents, so it does not address confidentiality or integrity. It is primarily a data lifecycle and recovery control, not a direct security control for protecting sensitive CloudTrail data.
- ✗
Enable multi-factor authentication (MFA) for CloudTrail.
Why it's wrong here
Multi-factor authentication (MFA) is an IAM-level authentication mechanism for human users or principals initiating API calls, not a setting that can be enabled on the CloudTrail service itself. While you can use MFA Delete to protect S3 bucket object versions from deletion, CloudTrail does not support an MFA feature for log delivery or access. Therefore, this option is invalid because it misunderstands the scope of MFA and does not provide any direct protection for the CloudTrail log files.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.