SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is configuring AWS CloudTrail to monitor data events for S3 objects. Which TWO of the following must be enabled to log object-level operations? (Select TWO.)
⚠ Common exam trap
Watch out — candidates often confuse management events (which log bucket-level actions) with data events (which log object-level actions), leading them to select Option C instead of recognizing that both data events and a specific bucket ARN or prefix are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable data events in the CloudTrail trail.
CloudTrail data events capture S3 object-level operations such as GetObject, PutObject, and DeleteObject. To enable this, you must explicitly select 'Data events' in the CloudTrail trail configuration, as management events only cover bucket-level operations like CreateBucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable data events in the CloudTrail trail.
Why this is correct
CloudTrail data events record S3 object-level operations such as GetObject, PutObject, and DeleteObject. Enabling data events is essential because management events only cover control-plane actions (e.g., bucket creation or policy changes), not the actual access to objects. Data events must be explicitly enabled in the trail, as they are not on by default due to their high volume, but they are exactly what you need to monitor object-level activity.
- ✗
Enable S3 server access logs on the bucket.
Why it's wrong here
S3 server access logs are generated by S3 itself, providing detailed records of requests made to a bucket, but they are a completely separate mechanism from CloudTrail. They are delivered to a destination bucket in a specific log format and are not integrated into CloudTrail trail configuration or event history. For monitoring via CloudTrail, you must enable data events; S3 server access logs are an alternative logging path, not a substitute or prerequisite.
- ✗
Enable management events in the CloudTrail trail.
Why it's wrong here
Management events in CloudTrail record control-plane operations on S3, such as creating a bucket, configuring lifecycle rules, or changing bucket policies. While management events are enabled by default in a trail, they do not capture object-level operations like reads or writes to individual objects. To monitor object access, you specifically need data events, so relying on management events alone will leave a critical gap in visibility.
- ✗
Enable S3 Object Lambda.
Why it's wrong here
S3 Object Lambda is a feature that lets you invoke custom Lambda functions on data retrieved from S3 before it is returned to the caller, enabling on-the-fly transformation or redaction. It has no role in logging or monitoring object activity; it processes requests in the data path but does not record or emit access logs. Enabling Object Lambda would add processing overhead without providing any audit trail for object-level operations.
- ✓
Specify the S3 bucket ARN or prefix in the trail configuration.
Why this is correct
In a CloudTrail trail, enabling data events for S3 requires you to explicitly specify the resources to monitor, either by bucket ARN or by a prefix for a subset of objects. Without this specification, CloudTrail cannot know which buckets to capture object-level events for, leaving the trail unable to record the desired activity. This configuration step is a required complement to enabling data events, ensuring the trail logs the exact S3 resources you intend to monitor.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.