SCS-C02 Infrastructure Security Practice Question
A company wants to use AWS CloudTrail to log all API calls in an AWS account. The security engineer needs to ensure that the logs are encrypted at rest and are accessible only to authorized personnel. Which THREE steps should the engineer take? (Choose THREE.)
⚠ Common exam trap
SCS-C02 often tests the difference between encryption at rest, encryption in transit, and access control — candidates incorrectly pick MFA Delete or SCPs thinking they provide confidentiality of log data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable server-side encryption on the S3 bucket that stores CloudTrail logs.
Option B is correct because enabling server-side encryption (SSE-S3, SSE-KMS, or SSE-C) on the S3 bucket that stores CloudTrail logs ensures the log objects are encrypted at rest, satisfying the encryption requirement. Option D is correct because an IAM policy scoped to specific users or roles enforces least-privilege access, ensuring only authorized personnel can read the CloudTrail log objects. Option E is correct because a bucket policy condition requiring aws:SecureTransport=true denies any non-TLS (HTTP) requests, protecting logs in transit and preventing unencrypted access. Option A does not belong because MFA delete protects against accidental or malicious deletion of objects but does not provide encryption at rest or restrict read access to authorized personnel. Option C does not belong because an SCP attached to the root account only sets permission guardrails for accounts in an organization and does not encrypt CloudTrail logs or grant/restrict access to the specific S3 bucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable MFA delete on the S3 bucket.
Why it's wrong here
MFA delete on an S3 bucket requires an additional authentication factor before any versioned object can be permanently deleted or before versioning can be suspended, which protects against accidental or malicious deletions. It does not, however, provide any encryption or prevent an authorized-but-unintended viewer from reading the CloudTrail logs, so it is purely a data durability control rather than a confidentiality control. For securing CloudTrail log content, MFA delete is therefore irrelevant.
- ✓
Enable server-side encryption on the S3 bucket that stores CloudTrail logs.
Why this is correct
Enabling server-side encryption on the S3 bucket that stores CloudTrail logs ensures that every delivered log object is encrypted at rest, either with SSE-S3 using Amazon-managed keys or with SSE-KMS using a customer-managed key. This directly protects the audit trail from being read by anyone who obtains the underlying storage, and it is a core requirement for compliance frameworks that mandate encrypted audit data. CloudTrail supports SSE-KMS through its own integration, allowing you to control the encryption key separately from the bucket.
- ✗
Attach a service control policy (SCP) to the root account.
Why it's wrong here
Attaching a service control policy (SCP) to the root account is an AWS Organizations measure that sets a permission boundary for member accounts, but it does not encrypt data and does not enforce HTTPS or access controls on an S3 bucket. SCPs only restrict the maximum permissions that IAM principals can use; they cannot be used to selectively protect log objects, and they do not affect how the S3 service handles requests to a CloudTrail destination bucket. In fact, SCPs cannot limit the actions of the management account root user, so they are ineffectual for securing the log bucket.
- ✓
Create an IAM policy that grants access to the S3 bucket only to specific users or roles.
Why this is correct
Creating a tightly scoped IAM policy that grants access to the CloudTrail bucket to only specific users or roles directly enforces least privilege over who can read the API call history. For instance, an IAM policy with an Allow on s3:GetObject limited to the log bucket prefix and restricted to named auditor or security principals prevents broad application access to sensitive logs. This is a correct and necessary control, though it addresses access only and should be paired with encryption for full protection.
- ✓
Configure the S3 bucket policy to require encrypted connections (aws:SecureTransport).
Why this is correct
Configuring an S3 bucket policy with the aws:SecureTransport condition set to true denies any request made over unencrypted HTTP and forces all access to CloudTrail logs to use TLS/HTTPS. This protects the API log data while it is in transit, preventing an attacker on the network path from intercepting log contents or credentials. Because CloudTrail itself uses HTTPS when delivering logs, this condition does not block delivery and is a standard, correct safeguard for the log bucket.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.