Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company needs to monitor for unauthorized S3 bucket deletions. Which CloudWatch Logs metric filter should be used on CloudTrail logs?

⚠ Common exam trap

Many candidates confuse read-only or policy-modifying events (like `GetBucketAcl`, `PutBucketPolicy`, or `ListBuckets`) with the actual deletion event, failing to recognize that only `DeleteBucket` directly corresponds to bucket removal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

eventName = DeleteBucket

The CloudTrail event `DeleteBucket` is logged when an S3 bucket is deleted. By creating a CloudWatch Logs metric filter that matches `eventName = DeleteBucket` on the CloudTrail log group, you can trigger an alarm or automated response to detect unauthorized bucket deletions. This directly addresses the monitoring requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    eventName = GetBucketAcl

    Why it's wrong here

    GetBucketAcl is a read-only S3 API call that returns the access control list attached to a specific bucket. It performs no mutation of bucket state and cannot trigger the removal of the bucket, so a CloudTrail event for GetBucketAcl would never fire as a consequence of deleting a bucket. Filtering on this event would therefore miss the unauthorized deletion entirely because the deletion is logged as DeleteBucket, not as an ACL read.

  • ✓

    eventName = DeleteBucket

    Why this is correct

    DeleteBucket is the exact S3 management API invoked when a bucket is removed, and CloudTrail records it as eventName = DeleteBucket for each deletion attempt. An EventBridge rule or CloudWatch Logs metric filter targeting this event name catches both successful and failed deletion attempts, depending on the response elements. This is the only option that corresponds to the actual bucket deletion operation, making it the correct value to monitor.

  • ✗

    eventName = PutBucketPolicy

    Why it's wrong here

    PutBucketPolicy uploads a new bucket policy and binds it to the bucket, modifying who can access the bucket rather than destroying it. An attacker could abuse it to grant public access or escalate privileges, but the bucket remains present and available after a successful PutBucketPolicy call. Since bucket deletion is not performed by this API, monitoring PutBucketPolicy would alert on policy tampering, not on actual deletion of the bucket.

  • ✗

    eventName = ListBuckets

    Why it's wrong here

    ListBuckets is a metadata read operation that returns the names of buckets owned by the caller; it does not address or operate on any single bucket. This API call is commonly used by tools and does not require s3:ListBucket permission on a specific bucket because it is a service-level operation. It cannot delete anything, and a CloudTrail event for ListBuckets would not appear as part of a bucket deletion workflow, making it an incorrect filter for deletion monitoring.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.