Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company uses AWS Organizations with multiple accounts. The security team needs to centralize CloudTrail logs from all accounts into a single S3 bucket in the management account. Which configuration ensures that only the management account can delete the log files?

⚠ Common exam trap

It's easy for candidates to confuse MFA Delete (option C) with account-level access control, but MFA Delete only adds an authentication factor and does not restrict deletion to a specific AWS account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an S3 bucket policy that denies s3:DeleteObject unless the principal is the management account.

It uses an S3 bucket policy with a conditional deny that explicitly restricts the s3:DeleteObject action to only the management account. This ensures that even if an IAM user or role in a member account has S3 permissions, they cannot delete log files unless they are from the management account. The policy leverages the aws:PrincipalOrgID or a specific account ID condition to enforce this restriction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable S3 Object Lock on the bucket with governance mode.

    Why it's wrong here

    S3 Object Lock in governance mode is a WORM (write-once-read-many) retention feature that protects objects from deletion or overwrites until the retention period lapses. Users who possess the s3:BypassGovernanceRetention permission can delete locked objects, and nothing in governance mode restricts deletion to a particular AWS account such as the management account. Since this option neither prevents an authorized non-management account from deleting objects nor addresses the requirement of management-only deletion, it is incorrect.

  • ✗

    Use an S3 bucket policy that denies s3:DeleteObject for all principals.

    Why it's wrong here

    A bucket policy that denies s3:DeleteObject for all principals would block every AWS account, including the management account's root user and any IAM principals from that account, because bucket policy Deny statements take precedence over any other permissions. Consequently, the management account would be unable to delete objects, which directly contradicts the stated requirement that the management account must be the only one allowed to delete. This over-restrictive approach disables deletion for the very principal that needs to delete, making it an incorrect solution.

  • ✗

    Enable MFA Delete on the S3 bucket.

    Why it's wrong here

    MFA Delete requires the caller to provide a valid MFA token when permanently deleting object versions or suspending versioning on a bucket, but it does not limit which AWS account or principal can perform the deletion. An IAM user from a non-management account could still delete objects if they have s3:DeleteObject and can supply MFA credentials, so this does not achieve 'only the management account can delete.' Additionally, MFA Delete only applies to versioned buckets and version-level deletes, not to all s3:DeleteObject operations, making this option insufficient.

  • ✗

    Configure CloudTrail to automatically delete logs older than 90 days.

    Why it's wrong here

    CloudTrail does not automatically delete logs from S3; it only delivers audit logs to the configured bucket, and lifecycle retention is not a feature of CloudTrail itself. While you could attach an S3 Lifecycle rule to expire old objects, that would delete log objects on a schedule without regard to the principal performing the deletion. More fundamentally, this option is irrelevant to the requirement of controlling which account is allowed to delete objects, because it addresses log retention rather than access control.

  • ✓

    Use an S3 bucket policy that denies s3:DeleteObject unless the principal is the management account.

    Why this is correct

    The correct approach is to add a bucket policy with a Deny effect for s3:DeleteObject that includes a Condition such as StringNotEquals on aws:PrincipalAccount with the management account's ID. This denies deletion for every principal that is not in the management account, while excluding the management account itself from the Deny so that its principals can delete. By using this resource-based policy and the aws:PrincipalAccount condition key, you enforce that only users or roles from the management account can delete objects from the S3 bucket.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.