SCS-C02 Infrastructure Security Practice Question
A company is using AWS CloudTrail to log API calls. The security team wants to ensure that log files are not modified after they are created. Which feature should they enable?
⚠ Common exam trap
SCS-C02 often tests the confusion between encryption (confidentiality) and integrity validation (tamper detection) — candidates must not assume KMS encryption prevents log modification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log file integrity validation
CloudTrail log file integrity validation uses SHA-256 hashing and RSA digital signatures to create digest files that let you verify log files have not been altered or deleted after delivery. It is the native CloudTrail feature designed specifically for tamper detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server-side encryption with AWS KMS
Why it's wrong here
Server-side encryption with AWS KMS (SSE-KMS) encrypts CloudTrail log files at rest, protecting the confidentiality of the data from unauthorized readers. However, encryption does not create a cryptographic hash or digital signature that can detect whether a log file was altered after it was written. An attacker with write access to the S3 bucket could replace or modify log objects, and the encrypted state would remain intact, leaving tampering undetected. Thus, SSE-KMS addresses data privacy, not data integrity.
- ✓
Log file integrity validation
Why this is correct
Log file integrity validation is a CloudTrail feature that uses SHA-256 hashing and digital signatures to build a hash chain across log and digest files. CloudTrail periodically delivers a signed digest file that includes the hash of every log file delivered during that period and the hash of the previous digest. If anyone modifies or deletes a log after delivery, the hash stored in the next digest will not match, and the validation command will flag the discrepancy. This is the only option here that provides direct, detection-based integrity assurance for CloudTrail logs.
- ✗
S3 Object Lock
Why it's wrong here
S3 Object Lock enables a Write-Once-Read-Many (WORM) model that can prevent a CloudTrail log object from being deleted or overwritten while a retention period is active. However, it does not provide a cryptographic proof of integrity; if the lock is not applied to every object or an authorized user removes the lock after retention expires, modifications can still happen without detection. Moreover, Object Lock focuses on preventing changes, not on validating that historical log files remain byte-for-byte unchanged, which is exactly what log file integrity validation offers.
- ✗
CloudWatch Logs integration
Why it's wrong here
Integrating CloudTrail with CloudWatch Logs lets you stream events to a central destination for real-time alerts, metric filters, and queries. While CloudWatch Logs can help you monitor suspicious activity or produce alarms, it does not apply any hash or signature to the original CloudTrail log files in S3. The stream itself is a separate copy of the events, and tampering with the source log files would not be identified by CloudWatch Logs. Therefore, CloudWatch Logs is a monitoring tool, not an integrity-validation mechanism.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.