Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company stores data in Amazon S3 and uses AWS KMS with Customer Master Keys (CMKs) for encryption. The security team wants to audit when the CMK is used to decrypt data. Which of the following will provide this information?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail logs all KMS Decrypt API calls, which is exactly what is needed to audit CMK decryption. Option A (AWS Config) records configuration changes, not API calls. Option B (Amazon CloudWatch Logs) can store logs but does not generate the KMS decrypt logs itself; CloudTrail generates them. Option D (S3 server access logs) record requests to S3 objects, not the KMS decryption calls that happen when accessing encrypted objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a resource inventory and compliance service that records configuration changes to supported AWS resources and evaluates them against rules. It does not capture API activity or data-plane operations, so a KMS Decrypt call—which does not alter the KMS key's configuration—is invisible to Config. Even when a key policy or rotation setting changes, Config records only the resulting configuration state, not the identity or context of the decryption request.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is not a standalone capture point for KMS API calls; it is a destination for log data emitted by other services. To see KMS Decrypt events in CloudWatch Logs, you must first enable AWS CloudTrail and configure its trail to deliver events to a CloudWatch Logs log group. Without that CloudTrail integration, CloudWatch Logs has no native visibility into KMS key usage, so it cannot be used to audit orphaned or compromised keys.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the authoritative source for KMS API activity because it records KMS calls as data events, including Decrypt, Encrypt, GenerateDataKey, and ReEncrypt. Each KMS data event in CloudTrail includes the key ID, whether decryption succeeded, the principal and ARN of the caller, the source IP, and the request timestamp. By enabling CloudTrail data events for a customer-managed KMS key, you get a complete audit trail that you can search in Athena or deliver to CloudWatch Logs for alerting.

  • ✗

    S3 server access logs

    Why it's wrong here

    S3 server access logs are generated for requests sent to Amazon S3, such as GetObject or PutObject, and they contain fields like bucket, key, requester, and operation. They do not include KMS API call records, so a KMS Decrypt performed by S3 on your behalf when serving a server-side-encrypted object will not appear in these logs. The access log can indicate that a GET occurred, but to see the actual KMS Decrypt call, you must inspect CloudTrail KMS data events.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.