Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company stores sensitive customer data in Amazon S3. The security team has enabled default encryption with SSE-S3 on the bucket. The compliance team requires that all access to the bucket be logged and that any unauthorized access attempts be detected in real time. The company has AWS CloudTrail enabled. Which additional steps should the security team take to meet the compliance requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 server access logs and enable Amazon GuardDuty with S3 protection

Enabling S3 server access logs captures all requests to the bucket, satisfying the logging requirement, and Amazon GuardDuty with S3 protection can detect suspicious activity in real time, meeting the requirement for real-time detection of unauthorized access. Option B is incorrect because AWS Config rules monitor configuration changes, not real-time threat detection. Option C is incorrect because CloudTrail data events can log S3 operations, but Amazon Detective is for post-incident analysis, not real-time detection. Option D is incorrect because VPC Flow Logs log network traffic, not S3 access, and Amazon Athena is a query service, not a real-time detection tool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable S3 server access logs and enable Amazon GuardDuty with S3 protection

    Why this is correct

    S3 server access logs capture every request made to the bucket, including requester IP, IAM role/user, action, and HTTP status, providing a detailed audit trail for forensic analysis. Amazon GuardDuty's S3 protection continuously monitors object-level operations and uses threat intelligence and anomaly detection to flag suspicious patterns, such as mass downloads or access from unusual geographies, in near-real time. Together they deliver both historical evidence and proactive alerting, making this the only option that addresses both detection and investigation of unauthorized access.

  • ✗

    Enable AWS Config rules to detect unauthorized access

    Why it's wrong here

    AWS Config rules are designed to evaluate the configuration state of AWS resources against compliance policies, such as whether a bucket is public or has encryption enabled. They do not analyze access requests or API call patterns, and they operate on configuration changes or periodic compliance checks, not on real-time events. Therefore, enabling Config rules cannot detect an unauthorized read of an object, because that action does not constitute a configuration violation but an access event.

  • ✗

    Enable CloudTrail data events for the S3 bucket and use Amazon Detective

    Why it's wrong here

    CloudTrail data events can indeed log S3 object-level operations, but they only produce a log file; they do not provide real-time alerting or automated threat detection. Amazon Detective is a post-incident investigation service that ingests and analyzes historical data from CloudTrail and VPC Flow Logs using machine learning to help you determine why a security finding occurred, not to detect threats as they happen. This pairing is useful for a forensic review after a breach, but it would not promptly identify and flag unauthorized access to the sensitive customer data.

  • ✗

    Enable VPC Flow Logs and use Amazon Athena to analyze logs

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic to and from network interfaces in a VPC, such as source/destination addresses, ports, and protocol. They do not log S3 API requests made over the public endpoint or via an S3 gateway endpoint; the flow logs show connection-level traffic but not the object-level actions like GetObject or PutObject. Even when analyzed with Amazon Athena, VPC Flow Logs cannot tell you which user accessed which specific S3 object, so this approach would completely miss the unauthorized access to the customer data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.