SCS-C02 Security Logging and Monitoring Practice Question
A company stores sensitive data in Amazon S3 and wants to detect and alert on any public read access to objects. Which combination of services provides the most comprehensive solution?
⚠ Common exam trap
Many candidates confuse S3 event notifications (which only cover write/delete events) with server access logs (which cover all operations including reads), leading them to choose Option D, which cannot detect read access at all.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable S3 server access logging and use Amazon Athena to query logs, with CloudWatch Events to alert on specific patterns
S3 server access logs capture detailed records of all requests made to a bucket, including the requester, bucket name, request time, action, and response status. By using Amazon Athena to query these logs and CloudWatch Events to trigger alerts on patterns indicating public read access (e.g., a specific HTTP method like GET from an anonymous principal), you can detect and alert on unauthorized public reads comprehensively. This combination provides granular, queryable logging with event-driven alerting, covering both current and historical access patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable VPC Flow Logs and analyze for S3 traffic
Why it's wrong here
VPC Flow Logs capture IP-level traffic metadata such as source/destination addresses, ports, and protocol, but they do not record S3 API actions like GetObject, nor the S3 bucket name, object key, or requester identity. For traffic through a gateway endpoint, flow logs only show traffic to the S3 service prefix and cannot differentiate between public and private or identify whether an object was actually read. Therefore, analyzing flow logs cannot detect specific unauthorized reads of sensitive S3 data.
- ✗
Use AWS Config rules to check for public bucket policies and alert via SNS
Why it's wrong here
AWS Config rules evaluate the configuration of S3 buckets, such as whether bucket policies or ACLs grant public access, but they do not monitor or log individual object access events. A rule can alert you to a misconfigured public policy, but it cannot tell you whether an actual GET request was made by an anonymous user or which object was accessed. Thus, this approach fails to detect ongoing public reads or provide an audit trail of data exposure.
- ✓
Enable S3 server access logging and use Amazon Athena to query logs, with CloudWatch Events to alert on specific patterns
Why this is correct
S3 server access logging produces detailed log records containing the requester, bucket name, object key, action string (e.g., REST.GET.OBJECT), and response status for each API call. Querying these logs with Amazon Athena lets you filter for the 'Anonymous' requester and identify specific objects being read publicly. A scheduled Athena query orchestrated via CloudWatch Events (now Amazon EventBridge) can publish findings to SNS or Lambda, enabling alerting on suspicious read patterns.
- ✗
Enable S3 event notifications for all object-level events and send to Amazon SNS
Why it's wrong here
S3 event notifications support only specific object-level event types such as ObjectCreated, ObjectRemoved, and ObjectRestore, but they do not generate events for GET/read operations. Even if you enable all available event types, the notification payload does not include the requester's identity and cannot distinguish public from private access. Consequently, event notifications cannot detect or alert on anonymous reads of sensitive objects.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.