SCS-C02 Security Logging and Monitoring Practice Question
A company needs to centralize security logs from multiple AWS accounts and on-premises servers. The logs must be encrypted at rest and stored in a cost-effective manner. Which solution meets these requirements?
⚠ Common exam trap
A common mix-up: candidates choose Amazon CloudWatch Logs with KMS encryption (Option D) because it seems like a natural fit for log management, but they overlook the cost implications and the requirement for cost-effective storage, which S3 with SSE-S3 addresses more efficiently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Amazon S3 with server-side encryption (SSE-S3)
Amazon S3 with server-side encryption (SSE-S3) meets the requirements because it provides encryption at rest using AES-256, is cost-effective for log storage, and can centralize logs from multiple AWS accounts and on-premises servers via S3 Cross-Account Access and the S3 API. SSE-S3 is fully managed by AWS, requiring no additional key management overhead, and S3's lifecycle policies can transition older logs to lower-cost tiers like S3 Glacier for further cost savings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Amazon S3 Glacier with Vault Lock
Why it's wrong here
Amazon S3 Glacier with Vault Lock is unsuitable because the Glacier vault service is a cold archival tier with retrieval times ranging from minutes to hours, making it impractical for active log aggregation and compliance analysis that requires periodic access. Vault Lock enforces write-once-read-many (WORM) compliance, but it does nothing to address the need for ingest, partitioning, or query. For centralized security logs, you need a storage service that supports immediate writes and frequent reads; Glacier is designed for long-term archival, not the central repository for active security data.
- ✓
Use Amazon S3 with server-side encryption (SSE-S3)
Why this is correct
Amazon S3 with SSE-S3 is the correct choice because S3 provides a cost-effective, highly durable object store optimized for high-volume log ingestion and retention, and SSE-S3 automatically encrypts each object with strong AES-256 encryption managed by AWS. S3 integrates natively with CloudTrail, VPC Flow Logs, and AWS Config to centralize logs from multiple accounts, and it supports lifecycle policies that can later transition older logs to S3 Glacier for further cost reduction. The encrypted-at-rest capability satisfies compliance requirements without the operational overhead of managing customer keys.
- ✗
Use Amazon Kinesis Data Firehose to deliver logs to Amazon Redshift
Why it's wrong here
Using Kinesis Data Firehose to deliver logs directly to Redshift forces you to provision and maintain a cluster that is sized for peak ingestion, and Redshift's per-node pricing plus storage and I/O costs make it far more expensive for raw, high-volume security log retention. Redshift is a massively parallel data warehouse intended for complex analytics and query acceleration, not an immutable log repository; it also introduces schema design and data-loading constraints that complicate simply centralizing logs. The logs would consume limited Redshift storage and require compute for COPY commands, whereas an S3 data lake would be simpler and cheaper.
- ✗
Use Amazon CloudWatch Logs with KMS encryption
Why it's wrong here
CloudWatch Logs with KMS encryption is not cost-effective for long-term centralized security log storage because CloudWatch Logs pricing per GB ingested and stored is significantly higher than S3, and costs escalate as logs accumulate over multi-year compliance periods. While KMS provides envelope encryption for CloudWatch Logs, it adds key management overhead and does not solve the fundamental problem of expensive per-log-event processing and storage. CloudWatch Logs is better suited for real-time operations monitoring and metric filters, not as a high-volume, low-cost central archive for logs aggregated from many accounts.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.