Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company uses AWS Organizations with multiple accounts. The security team wants to centralize VPC Flow Logs from all accounts into a single S3 bucket in the security account. The flow logs are created in the member accounts and sent to the centralized bucket. However, the security team notices that flow logs from some member accounts are not being delivered. What is the most likely cause?

⚠ Common exam trap

Many exam-takers assume an IAM role in the member account is required (Option A), but AWS actually uses resource-based policies (S3 bucket policy) for cross-account VPC Flow Log delivery, not IAM roles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The S3 bucket policy does not grant write permissions to the member accounts.

VPC Flow Logs are delivered to an S3 bucket using the flow log publisher's IAM role, but the destination bucket must also have a bucket policy that explicitly grants the necessary permissions (e.g., s3:PutObject) to the member accounts' log delivery service. Without this policy, the S3 bucket will reject write requests from member accounts, causing flow logs to fail silently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The member accounts need an IAM role with permissions to write to the centralized bucket.

    Why it's wrong here

    Creating VPC Flow Logs to an S3 bucket in another account does not require an IAM role to be created and assumed in each member account. The destination bucket's resource policy must grant the flow logs delivery service (vpc-flow-logs.amazonaws.com) s3:PutObject permissions for the AWSLogs prefix, and the member account user only needs ec2:CreateFlowLogs. An IAM role in the member account would be unnecessary and would not solve the cross-account S3 authorization.

  • ✗

    CloudTrail must be enabled in each member account before VPC Flow Logs can be sent to a centralized bucket.

    Why it's wrong here

    CloudTrail and VPC Flow Logs are independent services with separate delivery mechanisms. A member account can publish VPC Flow Logs directly to a centralized S3 bucket without CloudTrail being enabled anywhere in the organization. CloudTrail would only be relevant if you also wanted to aggregate API activity logs, not flow-level network traffic.

  • ✓

    The S3 bucket policy does not grant write permissions to the member accounts.

    Why this is correct

    The most direct reason the flow logs fail is that the S3 bucket policy is missing an explicit Allow that lets the delivering VPC Flow Logs service write objects into the bucket. For cross-account delivery, the policy needs a statement with Principal as vpc-flow-logs.amazonaws.com (or the aggregated log delivery principal) and Action s3:PutObject on the destination prefix such as arn:aws:s3:::central-bucket/AWSLogs/<member-account-id>/*. Without this resource-based grant, S3 denies the write even if the member account has full IAM permissions.

  • ✗

    VPC Flow Logs cannot be aggregated across multiple AWS accounts.

    Why it's wrong here

    VPC Flow Logs from multiple AWS accounts can be aggregated by sending every account's flow logs to the same S3 destination bucket. Each account creates its own flow log with the bucket ARN as the destination, and S3 organizes the files under account-specific AWSLogs prefixes, allowing a central account to query or process them. The limitation is not aggregation but ensuring the bucket policy explicitly authorizes every member account's delivery service.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.