SCS-C02 Security Logging and Monitoring Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": "cloudtrail.amazonaws.com"
},
"Action": "s3:PutObject",
"Resource": "arn:aws:s3:::my-log-bucket/AWSLogs/*"
}
]
}A security engineer configured the S3 bucket policy shown above for CloudTrail log delivery, but CloudTrail is not delivering logs. What is the MOST likely reason?
⚠ Common exam trap
The trap here is that candidates often focus on the PutObject permission or the resource ARN, overlooking the mandatory GetBucketAcl permission that CloudTrail requires for initial validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy does not include s3:GetBucketAcl permission.
CloudTrail requires the s3:GetBucketAcl permission on the destination S3 bucket to verify that the bucket policy grants the necessary access. Without this permission, CloudTrail cannot confirm it has write access and will fail to deliver logs. The bucket policy must explicitly allow the CloudTrail service principal to perform GetBucketAcl and PutObject actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The policy does not include s3:GetBucketAcl permission.
Why this is correct
CloudTrail's bucket policy must explicitly grant the service principal cloudtrail.amazonaws.com both s3:GetBucketAcl and s3:PutObject permissions for the target bucket. s3:GetBucketAcl is what lets CloudTrail verify that the bucket's access control list permits CloudTrail to write and manage log objects; without this permission, CloudTrail aborts the delivery configuration with an access denial even if PutObject is correctly allowed. Therefore, omitting s3:GetBucketAcl is a direct cause of the 'bucket policy does not allow for S3 access' error.
- ✗
The bucket is in the wrong region.
Why it's wrong here
S3 bucket policies do not contain a region element: the resource ARN for S3 is always in the format arn:aws:s3:::bucket-name, with no region component (unlike most other AWS services that include a region in the ARN). A trail can also be configured to write logs to a bucket in any region, especially when using a multi-region trail or a centralized logging bucket in the organization's management account. Thus the bucket's physical region cannot be the reason the policy fails to validate.
- ✗
The resource ARN is incorrect.
Why it's wrong here
The resource ARN in a CloudTrail bucket policy is technically accurate and follows the required format: arn:aws:s3:::my-bucket for the bucket-level permissions and arn:aws:s3:::my-bucket/AWSLogs/aws-account-id/* to cover the log objects under the prefix. If either ARN were malformed or pointed to a different bucket, CloudTrail would not even start delivering logs. Since the ARN correctly references the intended bucket and prefix, an incorrect ARN is not the cause of the policy validation failure.
- ✗
The bucket does not have default encryption enabled.
Why it's wrong here
Default bucket encryption is not a prerequisite for CloudTrail log delivery. When no default encryption is configured, CloudTrail will encrypt log objects with SSE-S3 automatically, and if you need KMS-managed keys, you can explicitly set the encryption configuration in CloudTrail itself rather than relying on the bucket's default encryption. The bucket policy in question is used for access control and delivery permissions, not for enforcing encryption, so the absence of default encryption has no effect on whether the policy is accepted or log delivery succeeds.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.