Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses AWS CloudTrail to log all API activity. The security team needs to retain the logs for 7 years and ensure they are tamper-proof. Additionally, the team must be able to query the logs for investigations. Which solution meets these requirements?

⚠ Common exam trap

Candidates often choose CloudTrail Lake (Option A) because it offers built-in querying, but they overlook the tamper-proof requirement, which only S3 Object Lock can guarantee for long-term retention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store logs in an Amazon S3 bucket with S3 Object Lock enabled and query using Amazon Athena.

Amazon S3 Object Lock provides a write-once-read-many (WORM) model that prevents logs from being deleted or overwritten, ensuring tamper-proof retention for 7 years. Amazon Athena allows querying the logs directly in S3 using standard SQL, meeting the investigation requirement without needing to move data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store logs in AWS CloudTrail Lake and use the built-in query feature.

    Why it's wrong here

    CloudTrail Lake provides a managed event data store with a built-in query engine, but it does not deliver the immutable, WORM-style retention required for a long-term compliance archive. The underlying data store remains mutable and is subject to lifecycle or purge operations, and the built-in query feature is optimized for security analytics rather than flexible, full-SQL join/aggregation across large historical log sets.

  • ✗

    Store logs in Amazon CloudWatch Logs with a retention policy of 7 years.

    Why it's wrong here

    Amazon CloudWatch Logs is designed for operational monitoring and real-time log streaming, not for tamper-proof archival; any IAM principal with logs:DeleteLogStream or logs:PutLogEvents can alter or remove entries. Even with a 7-year retention policy, the logs are not write-once-read-many, so they cannot satisfy strict compliance requirements, and the Logs Insights query language is significantly more limited than Athena SQL for complex analytics.

  • ✗

    Store logs in an Amazon S3 bucket with standard settings and use Amazon S3 Select for querying.

    Why it's wrong here

    An ordinary S3 bucket without Object Lock is fully mutable — objects can be overwritten or deleted by any principal holding s3:PutObject or s3:DeleteObject, so it fails the WORM test for audit log preservation. S3 Select executes simple 'filter' queries against a single object at a time and does not support joins, CTE, or cross-object aggregation, making it inadequate for analyzing large-scale, partitioned CloudTrail log archives.

  • ✓

    Store logs in an Amazon S3 bucket with S3 Object Lock enabled and query using Amazon Athena.

    Why this is correct

    The correct solution combines S3 Object Lock in either governance or compliance mode with Amazon Athena. Object Lock enforces a retention period that prevents any user — including an AWS account root user — from deleting or overwriting log files, and Athena can directly query the partitioned S3 logs using standard SQL through the Glue Data Catalog. This yields a durable, tamper-evident, serverless analytics pipeline for long-term CloudTrail log storage.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.