Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is using AWS CloudTrail to log API calls. The security team needs to ensure that log files are not tampered with and can be used to verify integrity. Which feature should be enabled?

⚠ Common exam trap

Candidates often confuse data protection features (encryption, versioning, MFA delete) with integrity verification, which specifically requires cryptographic hash validation to detect tampering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable log file integrity validation in CloudTrail.

CloudTrail log file integrity validation uses a hash chain (SHA-256) to create a digest file that proves log files have not been modified, deleted, or tampered with since delivery. This feature allows you to verify that CloudTrail log files have remained unchanged, meeting the security team's requirement for integrity verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable MFA delete on the log bucket.

    Why it's wrong here

    MFA delete on the log bucket is an S3 bucket-level feature that requires a second authentication factor before permanently deleting object versions or changing the bucket's versioning state. While it provides strong protection against accidental or malicious deletion of log files, it does nothing to prevent an authorized user from modifying the contents of existing log objects or to detect that tampering has occurred. Integrity is about verifying that log data remains unchanged, not about preventing deletion, so MFA delete does not satisfy the stated requirement.

  • ✓

    Enable log file integrity validation in CloudTrail.

    Why this is correct

    CloudTrail log file integrity validation employs a SHA-256 hash chain to detect any modification, deletion, or forgery of log files. CloudTrail periodically creates signed digest files that list the hash of every log file delivered in that period along with the hash of the previous digest, and each digest is signed with a private key held by AWS. You can verify the signature using the publicly available key and recompute hashes to confirm the logs have not been altered, which directly addresses the need to ensure the API call history is trustworthy and tamper-evident.

  • ✗

    Enable server-side encryption with AWS KMS on the log bucket.

    Why it's wrong here

    Server-side encryption with AWS KMS protects the confidentiality of log files at rest by encrypting their contents, but it does not provide any integrity guarantees. An attacker with appropriate IAM permissions could still read, modify, or overwrite log files while the service is actively writing to the bucket, and encryption alone will not reveal such changes. Cryptography for privacy is fundamentally different from integrity verification, so SSE-KMS cannot detect or prove whether a log file has been tampered with.

  • ✗

    Enable S3 versioning on the log bucket.

    Why it's wrong here

    S3 versioning preserves every version of an object, so if a log file is overwritten or deleted, the original version is retained and can be restored. This prevents accidental data loss and provides a form of historical recovery, but it does not verify that any particular version matches what CloudTrail originally delivered. An attacker could modify the latest version or even alter older versions, and without a separate validity check such as hash-based integrity validation you have no way to know which version is authentic or whether unauthorized changes occurred.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.