Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company uses AWS CloudTrail to log all management events and data events for S3. The security team wants to detect any PutObject API calls that upload objects with server-side encryption disabled. Which solution is MOST efficient?

⚠ Common exam trap

It's easy for candidates to confuse GuardDuty or Macie as encryption compliance tools, but they are designed for threat detection and data classification, respectively, not for verifying encryption headers on API calls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable CloudTrail data events for S3 and create a CloudWatch metric filter to alert on PutObject calls without the x-amz-server-side-encryption header.

CloudTrail data events for S3 capture PutObject API calls, including request parameters. A CloudWatch metric filter can be configured to match PutObject events that lack the 'x-amz-server-side-encryption' header, indicating the object was uploaded without server-side encryption. This approach is efficient as it uses existing logging infrastructure without additional scanning or parsing overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon GuardDuty to detect unencrypted uploads.

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes AWS CloudTrail management events, VPC Flow Logs, and DNS logs to identify malicious activity such as crypto-mining, compromised credentials, or anomalous API calls; it does not ingest S3 data events or inspect uploaded object headers. Because the x-amz-server-side-encryption header is not part of GuardDuty's findings, it cannot tell you whether a PutObject call was unencrypted. GuardDuty would therefore fail to meet this requirement, even though it might flag related bucket anomalies.

  • ✗

    Use Amazon Macie to scan S3 objects for missing encryption.

    Why it's wrong here

    Amazon Macie is designed for sensitive data discovery and classification—it uses machine learning and pattern matching to locate personally identifiable information, access keys, or financial data in S3 objects, not to evaluate how those objects were encrypted. While Macie can report on S3 bucket-level access and data inventory, it does not inspect per-object request headers or the encryption mode supplied at upload time. Consequently, Macie would not detect that server-side encryption was disabled on a specific PutObject call.

  • ✗

    Enable S3 server access logs and parse them with Amazon Athena.

    Why it's wrong here

    S3 server access logs record all requests made to a bucket, including PutObject calls, but they do not capture the encryption state of the uploaded object. The security team specifically needs to detect objects uploaded with server-side encryption disabled, which requires examining the `x-amz-server-side-encryption` request header — a field absent from server access logs. This option is tempting because server access logs are commonly used for auditing S3 request activity, and Athena can efficiently query large log datasets; it would be the correct choice if the requirement were to analyse request patterns or source IP addresses rather than encryption attributes.

  • ✓

    Enable CloudTrail data events for S3 and create a CloudWatch metric filter to alert on PutObject calls without the x-amz-server-side-encryption header.

    Why this is correct

    The correct approach is to enable CloudTrail data events for the S3 bucket, because S3 data events record each PutObject API call, including request parameters such as the x-amz-server-side-encryption header when the caller supplies it. You can send those events to CloudWatch Logs and create a metric filter that matches PutObject events where that header is absent, then attach a CloudWatch alarm to notify the security team. This directly captures the encryption intent of the caller at upload time, which is exactly what the requirement asks for.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.