Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer is configuring a new AWS account and wants to ensure that all API activity is logged and that logs are protected from deletion. The engineer plans to use AWS CloudTrail and Amazon S3. Which TWO actions should the engineer take to meet these requirements? (Choose two.)

⚠ Common exam trap

Candidates often confuse log file validation or encryption with immutability; they do not prevent deletion, whereas S3 Object Lock does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Object Lock in compliance mode on the S3 bucket used for CloudTrail logs.

To log all API activity, a multi-region trail that logs management events is necessary. To protect logs from deletion, S3 Object Lock in compliance mode provides immutability. Other options either do not prevent deletion, provide only detection, or address confidentiality rather than integrity. Together, these two actions meet the requirements for logging and protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable CloudTrail log file validation to ensure logs are not tampered with.

    Why it's wrong here

    Log file validation creates a digest file that can be used to verify that logs have not been modified after delivery. However, it does not prevent deletion or modification; it only provides a way to detect tampering. It is a detective control, not a preventive one, and does not meet the requirement to protect logs from deletion.

  • ✗

    Configure the S3 bucket policy to deny deletion of objects by any principal except the security engineer's IAM role.

    Why it's wrong here

    A bucket policy can restrict deletion, but it is not as robust as Object Lock. An administrator with sufficient permissions could modify the bucket policy to allow deletion, or the security engineer's role could be compromised. This approach does not provide immutability and is not a recommended best practice for protecting audit logs.

  • ✓

    Enable S3 Object Lock in compliance mode on the S3 bucket used for CloudTrail logs.

    Why this is correct

    S3 Object Lock in compliance mode prevents objects from being deleted or overwritten for a specified retention period, even by the root user. This protects CloudTrail logs from tampering or deletion, satisfying the immutability requirement. It is a strong control that ensures logs cannot be altered, which is critical for security and compliance.

  • ✗

    Use AWS Key Management Service (AWS KMS) to encrypt the CloudTrail logs in the S3 bucket.

    Why it's wrong here

    Encrypting logs with KMS protects confidentiality but does not prevent deletion. An authorized user could still delete the objects if they have permissions. Encryption is important for data protection but does not address the immutability requirement. It is not one of the two actions needed to prevent log deletion.

  • ✓

    Create a CloudTrail trail that applies to all regions and logs management events.

    Why this is correct

    A multi-region trail ensures that API activity in all AWS regions is captured. Logging management events records control plane operations such as creating IAM roles or modifying security groups. This is essential to meet the requirement that all API activity is logged. Without a multi-region trail, activity in regions other than the home region would be missed, leaving gaps in the audit trail.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.