SCS-C02 Threat Detection and Incident Response Practice Question
A company uses AWS CloudTrail to log all API activity. The security team needs to retain the logs for 7 years and ensure they are tamper-proof. Additionally, the team must be able to query the logs for investigations. Which solution meets these requirements?
⚠ Common exam trap
Candidates often choose CloudTrail Lake (Option A) because it offers built-in querying, but they overlook the tamper-proof requirement, which only S3 Object Lock can guarantee for long-term retention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store logs in an Amazon S3 bucket with S3 Object Lock enabled and query using Amazon Athena.
Amazon S3 Object Lock provides a write-once-read-many (WORM) model that prevents logs from being deleted or overwritten, ensuring tamper-proof retention for 7 years. Amazon Athena allows querying the logs directly in S3 using standard SQL, meeting the investigation requirement without needing to move data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store logs in AWS CloudTrail Lake and use the built-in query feature.
Why it's wrong here
CloudTrail Lake provides a managed event data store with a built-in query engine, but it does not deliver the immutable, WORM-style retention required for a long-term compliance archive. The underlying data store remains mutable and is subject to lifecycle or purge operations, and the built-in query feature is optimized for security analytics rather than flexible, full-SQL join/aggregation across large historical log sets.
- ✗
Store logs in Amazon CloudWatch Logs with a retention policy of 7 years.
Why it's wrong here
Amazon CloudWatch Logs is designed for operational monitoring and real-time log streaming, not for tamper-proof archival; any IAM principal with logs:DeleteLogStream or logs:PutLogEvents can alter or remove entries. Even with a 7-year retention policy, the logs are not write-once-read-many, so they cannot satisfy strict compliance requirements, and the Logs Insights query language is significantly more limited than Athena SQL for complex analytics.
- ✗
Store logs in an Amazon S3 bucket with standard settings and use Amazon S3 Select for querying.
Why it's wrong here
An ordinary S3 bucket without Object Lock is fully mutable — objects can be overwritten or deleted by any principal holding s3:PutObject or s3:DeleteObject, so it fails the WORM test for audit log preservation. S3 Select executes simple 'filter' queries against a single object at a time and does not support joins, CTE, or cross-object aggregation, making it inadequate for analyzing large-scale, partitioned CloudTrail log archives.
- ✓
Store logs in an Amazon S3 bucket with S3 Object Lock enabled and query using Amazon Athena.
Why this is correct
The correct solution combines S3 Object Lock in either governance or compliance mode with Amazon Athena. Object Lock enforces a retention period that prevents any user — including an AWS account root user — from deleting or overwriting log files, and Athena can directly query the partitioned S3 logs using standard SQL through the Glue Data Catalog. This yields a durable, tamper-evident, serverless analytics pipeline for long-term CloudTrail log storage.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.