Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company uses AWS CloudTrail to log API activity. The security team wants to ensure that any modification to CloudTrail configuration is logged and that the logs are tamper-proof. Which feature should be enabled?

⚠ Common exam trap

Test-takers frequently confuse S3 Versioning (which provides object recovery) with cryptographic integrity validation, failing to recognize that only Log File Integrity Validation provides tamper-proof verification through digital signatures and hash chains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudTrail Log File Integrity Validation

CloudTrail Log File Integrity Validation (option C) uses a hash chain and digital signatures (SHA-256 hashing with RSA) to verify that log files have not been modified, deleted, or tampered with after delivery to the S3 bucket. This feature creates a digest file that contains the hash of each log file, and the digest files themselves are signed, enabling the security team to detect any unauthorized changes to CloudTrail configuration logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    S3 MFA Delete on the CloudTrail S3 bucket

    Why it's wrong here

    S3 MFA Delete on the CloudTrail S3 bucket is incorrect because it only requires multi-factor authentication for permanent deletion of object versions or toggling versioning. It does not provide any means to detect modification or tampering of existing CloudTrail log files, nor does it verify the authenticity of the logs. Thus, while it adds a protection against deletion, it does not satisfy the requirement to validate log file integrity.

  • ✗

    S3 Versioning on the CloudTrail S3 bucket

    Why it's wrong here

    S3 Versioning on the CloudTrail S3 bucket is incorrect because it preserves multiple versions of an object, allowing recovery from overwrites or accidental deletions, but it does not cryptographically validate the content of the log files. An attacker could modify a log file undetected, and versioning would simply create a new version without alerting anyone to the change. Therefore, it does not provide integrity verification.

  • ✓

    CloudTrail Log File Integrity Validation

    Why this is correct

    CloudTrail Log File Integrity Validation is correct because it generates a SHA-256 hash of each log file and signs it with a private key, enabling you to detect any tampering or deletion of log files. You can retrieve the public key from a pre-signed URL to verify both the hash and the digital signature, ensuring the logs have not been altered. This provides strong, cryptographic proof of integrity, which is exactly what the requirement demands.

  • ✗

    CloudWatch Logs log stream encryption

    Why it's wrong here

    CloudWatch Logs log stream encryption is incorrect because encryption with AWS KMS protects the confidentiality of log data at rest but does not provide any integrity checking or tamper detection. Encryption only prevents unauthorized reading of the logs; it does not include a hash or digital signature to prove the logs have not been modified. Therefore, it does not address the need to validate that the CloudTrail log files have remained untouched.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.