Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company uses AWS CloudTrail and wants to ensure that log files are encrypted at rest and that access to the logs is logged. Which combination of S3 features should be enabled on the destination bucket?

⚠ Common exam trap

Many candidates confuse server access logging with CloudTrail itself, thinking CloudTrail already logs access to the S3 bucket, but CloudTrail logs API calls to the bucket (e.g., PutObject), while server access logging captures every HTTP request at the object level, including reads and anonymous requests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Default encryption and server access logging

Enabling default encryption on the S3 bucket ensures that all CloudTrail log files are encrypted at rest using SSE-S3 or SSE-KMS, satisfying the encryption requirement. Enabling server access logging on the same bucket creates detailed records of every request made to the bucket, including who accessed the logs and from where, thus logging access to the logs themselves. This combination directly addresses both requirements: encryption at rest and access logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    S3 Transfer Acceleration and default encryption

    Why it's wrong here

    S3 Transfer Acceleration only optimizes upload speed over Amazon's edge network and does not alter how objects are stored or protected. Combining it with default encryption still provides no server access logging, so CloudTrail log files would be encrypted but the bucket's access activity would not be recorded. The requirement is for both encryption and auditability, not faster ingestion.

  • ✗

    MFA Delete and versioning

    Why it's wrong here

    Versioning retains every object version, and MFA Delete requires an additional authentication factor before permanent deletions can occur, which strengthens deletion protection. However, neither mechanism encrypts objects or logs request-level activity, so it fails to deliver the encryption-at-rest and access-accounting capabilities the company needs. This combination addresses durability and integrity, not confidentiality or logging.

  • ✓

    Default encryption and server access logging

    Why this is correct

    Default encryption on the destination S3 bucket automatically applies server-side encryption (SSE-S3, SSE-KMS, or SSE-C) to every CloudTrail log object, satisfying the encryption-at-rest requirement. Server access logging captures detailed records of every request made to the bucket, including the source IP, requester, and operation, which provides the needed audit trail of access to those logs. Together, these features ensure the CloudTrail logs are protected and their access activity is observable.

  • ✗

    S3 Object Lock and versioning

    Why it's wrong here

    S3 Object Lock, when enabled with versioning, places objects into a WORM state that prevents them from being overwritten or deleted for a specified retention period, which is useful for compliance. Yet it does not encrypt the contents of the log files and it does not generate or store access logs, so unauthorized reads would still be unrecorded and data would remain plaintext. This choice meets retention goals, but not the stated encryption and logging requirements.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.