SCS-C02 Security Logging and Monitoring Practice Question
A company uses AWS CloudTrail to log API activity. The security team wants to ensure that any modification to CloudTrail configuration is logged and that the logs are tamper-proof. Which feature should be enabled?
⚠ Common exam trap
Test-takers frequently confuse S3 Versioning (which provides object recovery) with cryptographic integrity validation, failing to recognize that only Log File Integrity Validation provides tamper-proof verification through digital signatures and hash chains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudTrail Log File Integrity Validation
CloudTrail Log File Integrity Validation (option C) uses a hash chain and digital signatures (SHA-256 hashing with RSA) to verify that log files have not been modified, deleted, or tampered with after delivery to the S3 bucket. This feature creates a digest file that contains the hash of each log file, and the digest files themselves are signed, enabling the security team to detect any unauthorized changes to CloudTrail configuration logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
S3 MFA Delete on the CloudTrail S3 bucket
Why it's wrong here
S3 MFA Delete on the CloudTrail S3 bucket is incorrect because it only requires multi-factor authentication for permanent deletion of object versions or toggling versioning. It does not provide any means to detect modification or tampering of existing CloudTrail log files, nor does it verify the authenticity of the logs. Thus, while it adds a protection against deletion, it does not satisfy the requirement to validate log file integrity.
- ✗
S3 Versioning on the CloudTrail S3 bucket
Why it's wrong here
S3 Versioning on the CloudTrail S3 bucket is incorrect because it preserves multiple versions of an object, allowing recovery from overwrites or accidental deletions, but it does not cryptographically validate the content of the log files. An attacker could modify a log file undetected, and versioning would simply create a new version without alerting anyone to the change. Therefore, it does not provide integrity verification.
- ✓
CloudTrail Log File Integrity Validation
Why this is correct
CloudTrail Log File Integrity Validation is correct because it generates a SHA-256 hash of each log file and signs it with a private key, enabling you to detect any tampering or deletion of log files. You can retrieve the public key from a pre-signed URL to verify both the hash and the digital signature, ensuring the logs have not been altered. This provides strong, cryptographic proof of integrity, which is exactly what the requirement demands.
- ✗
CloudWatch Logs log stream encryption
Why it's wrong here
CloudWatch Logs log stream encryption is incorrect because encryption with AWS KMS protects the confidentiality of log data at rest but does not provide any integrity checking or tamper detection. Encryption only prevents unauthorized reading of the logs; it does not include a hash or digital signature to prove the logs have not been modified. Therefore, it does not address the need to validate that the CloudTrail log files have remained untouched.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.