SCS-C02 Data Protection Practice Question
A company stores data in Amazon S3 and uses AWS KMS with Customer Master Keys (CMKs) for encryption. The security team wants to audit when the CMK is used to decrypt data. Which of the following will provide this information?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail logs all KMS Decrypt API calls, which is exactly what is needed to audit CMK decryption. Option A (AWS Config) records configuration changes, not API calls. Option B (Amazon CloudWatch Logs) can store logs but does not generate the KMS decrypt logs itself; CloudTrail generates them. Option D (S3 server access logs) record requests to S3 objects, not the KMS decryption calls that happen when accessing encrypted objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config is a resource inventory and compliance service that records configuration changes to supported AWS resources and evaluates them against rules. It does not capture API activity or data-plane operations, so a KMS Decrypt call—which does not alter the KMS key's configuration—is invisible to Config. Even when a key policy or rotation setting changes, Config records only the resulting configuration state, not the identity or context of the decryption request.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is not a standalone capture point for KMS API calls; it is a destination for log data emitted by other services. To see KMS Decrypt events in CloudWatch Logs, you must first enable AWS CloudTrail and configure its trail to deliver events to a CloudWatch Logs log group. Without that CloudTrail integration, CloudWatch Logs has no native visibility into KMS key usage, so it cannot be used to audit orphaned or compromised keys.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the authoritative source for KMS API activity because it records KMS calls as data events, including Decrypt, Encrypt, GenerateDataKey, and ReEncrypt. Each KMS data event in CloudTrail includes the key ID, whether decryption succeeded, the principal and ARN of the caller, the source IP, and the request timestamp. By enabling CloudTrail data events for a customer-managed KMS key, you get a complete audit trail that you can search in Athena or deliver to CloudWatch Logs for alerting.
- ✗
S3 server access logs
Why it's wrong here
S3 server access logs are generated for requests sent to Amazon S3, such as GetObject or PutObject, and they contain fields like bucket, key, requester, and operation. They do not include KMS API call records, so a KMS Decrypt performed by S3 on your behalf when serving a server-side-encrypted object will not appear in these logs. The access log can indicate that a GET occurred, but to see the actual KMS Decrypt call, you must inspect CloudTrail KMS data events.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.