SCS-C02 Data Protection Practice Question
A company stores sensitive customer data in Amazon S3. The security team has enabled default encryption with SSE-S3 on the bucket. The compliance team requires that all access to the bucket be logged and that any unauthorized access attempts be detected in real time. The company has AWS CloudTrail enabled. Which additional steps should the security team take to meet the compliance requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable S3 server access logs and enable Amazon GuardDuty with S3 protection
Enabling S3 server access logs captures all requests to the bucket, satisfying the logging requirement, and Amazon GuardDuty with S3 protection can detect suspicious activity in real time, meeting the requirement for real-time detection of unauthorized access. Option B is incorrect because AWS Config rules monitor configuration changes, not real-time threat detection. Option C is incorrect because CloudTrail data events can log S3 operations, but Amazon Detective is for post-incident analysis, not real-time detection. Option D is incorrect because VPC Flow Logs log network traffic, not S3 access, and Amazon Athena is a query service, not a real-time detection tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable S3 server access logs and enable Amazon GuardDuty with S3 protection
Why this is correct
S3 server access logs capture every request made to the bucket, including requester IP, IAM role/user, action, and HTTP status, providing a detailed audit trail for forensic analysis. Amazon GuardDuty's S3 protection continuously monitors object-level operations and uses threat intelligence and anomaly detection to flag suspicious patterns, such as mass downloads or access from unusual geographies, in near-real time. Together they deliver both historical evidence and proactive alerting, making this the only option that addresses both detection and investigation of unauthorized access.
- ✗
Enable AWS Config rules to detect unauthorized access
Why it's wrong here
AWS Config rules are designed to evaluate the configuration state of AWS resources against compliance policies, such as whether a bucket is public or has encryption enabled. They do not analyze access requests or API call patterns, and they operate on configuration changes or periodic compliance checks, not on real-time events. Therefore, enabling Config rules cannot detect an unauthorized read of an object, because that action does not constitute a configuration violation but an access event.
- ✗
Enable CloudTrail data events for the S3 bucket and use Amazon Detective
Why it's wrong here
CloudTrail data events can indeed log S3 object-level operations, but they only produce a log file; they do not provide real-time alerting or automated threat detection. Amazon Detective is a post-incident investigation service that ingests and analyzes historical data from CloudTrail and VPC Flow Logs using machine learning to help you determine why a security finding occurred, not to detect threats as they happen. This pairing is useful for a forensic review after a breach, but it would not promptly identify and flag unauthorized access to the sensitive customer data.
- ✗
Enable VPC Flow Logs and use Amazon Athena to analyze logs
Why it's wrong here
VPC Flow Logs capture metadata about IP traffic to and from network interfaces in a VPC, such as source/destination addresses, ports, and protocol. They do not log S3 API requests made over the public endpoint or via an S3 gateway endpoint; the flow logs show connection-level traffic but not the object-level actions like GetObject or PutObject. Even when analyzed with Amazon Athena, VPC Flow Logs cannot tell you which user accessed which specific S3 object, so this approach would completely miss the unauthorized access to the customer data.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.