SCS-C02 Security Logging and Monitoring Practice Question
A company needs to monitor for unauthorized S3 bucket deletions. Which CloudWatch Logs metric filter should be used on CloudTrail logs?
⚠ Common exam trap
Many candidates confuse read-only or policy-modifying events (like `GetBucketAcl`, `PutBucketPolicy`, or `ListBuckets`) with the actual deletion event, failing to recognize that only `DeleteBucket` directly corresponds to bucket removal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
eventName = DeleteBucket
The CloudTrail event `DeleteBucket` is logged when an S3 bucket is deleted. By creating a CloudWatch Logs metric filter that matches `eventName = DeleteBucket` on the CloudTrail log group, you can trigger an alarm or automated response to detect unauthorized bucket deletions. This directly addresses the monitoring requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
eventName = GetBucketAcl
Why it's wrong here
GetBucketAcl is a read-only S3 API call that returns the access control list attached to a specific bucket. It performs no mutation of bucket state and cannot trigger the removal of the bucket, so a CloudTrail event for GetBucketAcl would never fire as a consequence of deleting a bucket. Filtering on this event would therefore miss the unauthorized deletion entirely because the deletion is logged as DeleteBucket, not as an ACL read.
- ✓
eventName = DeleteBucket
Why this is correct
DeleteBucket is the exact S3 management API invoked when a bucket is removed, and CloudTrail records it as eventName = DeleteBucket for each deletion attempt. An EventBridge rule or CloudWatch Logs metric filter targeting this event name catches both successful and failed deletion attempts, depending on the response elements. This is the only option that corresponds to the actual bucket deletion operation, making it the correct value to monitor.
- ✗
eventName = PutBucketPolicy
Why it's wrong here
PutBucketPolicy uploads a new bucket policy and binds it to the bucket, modifying who can access the bucket rather than destroying it. An attacker could abuse it to grant public access or escalate privileges, but the bucket remains present and available after a successful PutBucketPolicy call. Since bucket deletion is not performed by this API, monitoring PutBucketPolicy would alert on policy tampering, not on actual deletion of the bucket.
- ✗
eventName = ListBuckets
Why it's wrong here
ListBuckets is a metadata read operation that returns the names of buckets owned by the caller; it does not address or operate on any single bucket. This API call is commonly used by tools and does not require s3:ListBucket permission on a specific bucket because it is a service-level operation. It cannot delete anything, and a CloudTrail event for ListBuckets would not appear as part of a bucket deletion workflow, making it an incorrect filter for deletion monitoring.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.