SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is configuring CloudTrail to log all management events across all regions. The engineer wants to ensure that log files are delivered to an S3 bucket owned by a separate AWS account for centralized auditing. Which additional configuration is required to allow the S3 bucket in the other account to receive these logs?
⚠ Common exam trap
Candidates often confuse cross-account S3 access with IAM roles, assuming CloudTrail needs an IAM role in the source account to assume permissions, when in fact CloudTrail uses a service principal and a resource-based bucket policy on the destination bucket.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a bucket policy to the destination S3 bucket that allows CloudTrail to write objects.
CloudTrail delivers log files to an S3 bucket in a separate account by writing objects across accounts. The destination bucket must have a bucket policy that explicitly grants CloudTrail (the service principal `cloudtrail.amazonaws.com`) permission to write objects (e.g., `s3:PutObject`). Without this policy, CloudTrail cannot deliver logs to the cross-account bucket, even if the source account has proper CloudTrail configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an S3 bucket policy on the source account's bucket to allow cross-account access.
Why it's wrong here
A bucket policy on the source account's S3 bucket is irrelevant for cross-account CloudTrail delivery because CloudTrail never writes objects to the source account's own bucket when the designated destination bucket exists elsewhere. Cross-account log delivery is authorized exclusively by the resource-based policy attached to the destination bucket, which explicitly grants CloudTrail's service principal write access. Applying a policy to the source bucket would only affect that bucket's own object permissions and would not give CloudTrail any path to the destination account's bucket.
- ✗
Enable S3 server-side encryption with KMS on the destination bucket.
Why it's wrong here
Enabling SSE-KMS on the destination bucket is an optional security measure, not a prerequisite for cross-account CloudTrail delivery; CloudTrail can still deliver logs to a bucket encrypted with SSE-S3 without any additional configuration. If you do choose SSE-KMS, you must also grant the CloudTrail service principal permissions on the KMS key, but simply turning on encryption neither grants CloudTrail S3 write permission nor establishes the cross-account trust required for delivery. The missing piece is always the destination bucket policy, not the bucket's encryption setting.
- ✗
Create an IAM role in the source account and attach a trust policy for CloudTrail.
Why it's wrong here
CloudTrail's cross-account S3 delivery does not involve IAM roles; the CloudTrail service calls the destination S3 bucket directly using its own service principal, so a role created in the source account cannot authorize writes to another account's bucket. An IAM role with a trust policy for CloudTrail would allow CloudTrail to assume the role, but CloudTrail does not use that mechanism for S3 delivery — that pattern is more relevant to CloudWatch Logs delivery, which uses a role. The source account's identity-based permissions are also irrelevant because the destination bucket is not in the source account; only the destination bucket's resource policy controls access.
- ✓
Add a bucket policy to the destination S3 bucket that allows CloudTrail to write objects.
Why this is correct
The destination bucket must have a resource-based policy that explicitly allows CloudTrail's service principal (`cloudtrail.amazonaws.com`) to write objects into that bucket, typically with `s3:PutObject` permission and a condition restricting access to the source account's trail. This bucket policy is the only mechanism that authorizes the cross-account write path because CloudTrail in the source account presents no IAM role or source-account user credentials to S3. For a complete setup, the trail in the source account references the destination bucket ARN, and the bucket policy also includes `s3:GetBucketAcl` or `s3:GetBucketLocation` as needed for CloudTrail to verify bucket ownership. Without this policy, CloudTrail will fail with an access denied error during delivery.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.