SCS-C02 Security Logging and Monitoring Practice Question
A company uses AWS CloudTrail and wants to ensure that log files are encrypted at rest and that access to the logs is logged. Which combination of S3 features should be enabled on the destination bucket?
⚠ Common exam trap
Many candidates confuse server access logging with CloudTrail itself, thinking CloudTrail already logs access to the S3 bucket, but CloudTrail logs API calls to the bucket (e.g., PutObject), while server access logging captures every HTTP request at the object level, including reads and anonymous requests.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Default encryption and server access logging
Enabling default encryption on the S3 bucket ensures that all CloudTrail log files are encrypted at rest using SSE-S3 or SSE-KMS, satisfying the encryption requirement. Enabling server access logging on the same bucket creates detailed records of every request made to the bucket, including who accessed the logs and from where, thus logging access to the logs themselves. This combination directly addresses both requirements: encryption at rest and access logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
S3 Transfer Acceleration and default encryption
Why it's wrong here
S3 Transfer Acceleration only optimizes upload speed over Amazon's edge network and does not alter how objects are stored or protected. Combining it with default encryption still provides no server access logging, so CloudTrail log files would be encrypted but the bucket's access activity would not be recorded. The requirement is for both encryption and auditability, not faster ingestion.
- ✗
MFA Delete and versioning
Why it's wrong here
Versioning retains every object version, and MFA Delete requires an additional authentication factor before permanent deletions can occur, which strengthens deletion protection. However, neither mechanism encrypts objects or logs request-level activity, so it fails to deliver the encryption-at-rest and access-accounting capabilities the company needs. This combination addresses durability and integrity, not confidentiality or logging.
- ✓
Default encryption and server access logging
Why this is correct
Default encryption on the destination S3 bucket automatically applies server-side encryption (SSE-S3, SSE-KMS, or SSE-C) to every CloudTrail log object, satisfying the encryption-at-rest requirement. Server access logging captures detailed records of every request made to the bucket, including the source IP, requester, and operation, which provides the needed audit trail of access to those logs. Together, these features ensure the CloudTrail logs are protected and their access activity is observable.
- ✗
S3 Object Lock and versioning
Why it's wrong here
S3 Object Lock, when enabled with versioning, places objects into a WORM state that prevents them from being overwritten or deleted for a specified retention period, which is useful for compliance. Yet it does not encrypt the contents of the log files and it does not generate or store access logs, so unauthorized reads would still be unrecorded and data would remain plaintext. This choice meets retention goals, but not the stated encryption and logging requirements.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.