SCS-C02 Threat Detection and Incident Response Practice Question
A company uses AWS Organizations with multiple accounts. The security team wants to centrally collect and analyze VPC Flow Logs from all accounts. What is the MOST efficient way to achieve this?
⚠ Common exam trap
Many exam-takers assume Firewall Manager (Option A) handles log aggregation, but it only manages the configuration policy, not the actual log delivery destination; similarly, many mistakenly think CloudWatch Logs (Option B) supports cross-account delivery natively, which it does not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure VPC Flow Logs to deliver to a central S3 bucket in the security account, and use a bucket policy that grants the source accounts permission to write.
It uses a central S3 bucket in the security account with a bucket policy that grants the PutObject permission to the VPC Flow Logs delivery service from each source account. This is the most efficient approach as it avoids per-account configuration overhead, eliminates the need for cross-account replication, and provides a single location for centralized analysis using services like Amazon Athena or Amazon QuickSight.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Firewall Manager to deploy VPC Flow Logs and aggregate logs in a single account.
Why it's wrong here
AWS Firewall Manager can centrally deploy VPC Flow Logs as a policy across organization accounts, but it is a policy management and compliance tool, not a log aggregation service. It cannot write logs to a central bucket or log group; each account still needs its own delivery target, leaving log correlation as a separate integration.
- ✗
Configure VPC Flow Logs to deliver to a central CloudWatch Logs log group in the management account.
Why it's wrong here
VPC Flow Logs can publish only to a CloudWatch Logs log group in the same account where the flow log is created. Aggregating to the management account would require building a cross-account subscription pipeline—one subscription filter per source account sending to a Kinesis Data Stream or Lambda—then into a central log group, which is not a native VPC Flow Logs delivery target.
- ✓
Configure VPC Flow Logs to deliver to a central S3 bucket in the security account, and use a bucket policy that grants the source accounts permission to write.
Why this is correct
VPC Flow Logs natively support delivering to an S3 bucket that is owned by a different account, such as a security account. The central bucket policy must grant the delivery.logs.amazonaws.com service principal permission to PutObject, with an aws:SourceAccount condition restricting writes to the authorized source accounts. This configures direct, server-side log delivery without any interim services or replication.
- ✗
Set up VPC Flow Logs in each account to deliver to local S3 buckets, then use S3 replication to copy to a central bucket.
Why it's wrong here
While you could configure VPC Flow Logs to land in a local S3 bucket and then use S3 Replication to copy objects to a central bucket, this approach requires enabling versioning on both buckets and creating replication rules and IAM roles. Replication is asynchronous, adds storage and request costs, and doesn’t backfill pre-existing logs—so it is strictly more complex and expensive than the native cross-account S3 destination, which delivers directly from the flow log publisher.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.