SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is designing a centralized logging solution for multiple AWS accounts. Which TWO services should be used to aggregate logs from all accounts into a single account? (Choose TWO.)
⚠ Common exam trap
Test-takers frequently confuse log destinations (like S3) with log aggregation services, failing to recognize that S3 is a passive storage target and does not actively collect or aggregate logs from multiple accounts without the orchestration provided by CloudWatch Logs or CloudTrail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Logs
Amazon CloudWatch Logs can receive log data from multiple AWS accounts via cross-account subscription filters, allowing a centralized logging account to aggregate logs from all source accounts. AWS CloudTrail can be configured to deliver trail logs from multiple accounts to a single S3 bucket in a central account, enabling consolidated audit logging. Together, these two services provide a comprehensive centralized logging solution for multi-account environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config records configuration state and changes for AWS resources, and it can aggregate that configuration and compliance data across accounts using an aggregator. It does not collect runtime application logs, security findings, or user activity logs, which are the typical inputs of a centralized logging solution. For log aggregation you need a pipeline that streams log events, not a configuration recorder.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture IP traffic metadata for network interfaces and can be published to Amazon S3 or CloudWatch Logs, but they are not delivered directly into a central account. To centralize them you would need additional steps such as S3 bucket replication, cross-account bucket policies, or a CloudWatch Logs subscription filter to forward them. They are therefore a log source that requires extra architecture, not a standalone centralized log aggregation service.
- ✓
Amazon CloudWatch Logs
Why this is correct
Amazon CloudWatch Logs is correct because you can create a cross-account destination in a central account—for example, a Kinesis Data Streams stream or an Amazon OpenSearch Service cluster—and attach a subscription filter in each source account's log group to stream log events to that destination. The CloudWatch Logs destination resource holds the ARN of the central resource and an IAM role that grants the source account permission to send data. This natively supports the real-time, centralized log collection that the scenario requires.
- ✗
Amazon S3
Why it's wrong here
Amazon S3 is an object storage service that can act as a durable landing zone for logs, but it does not provide the aggregation logic needed to collect logs from multiple sources and accounts. Services like CloudTrail and VPC Flow Logs can deliver files into a central bucket, and S3 Replication can copy objects, but S3 cannot subscribe to CloudWatch log events or filter/forward them. In a centralized logging design, S3 should be the final repository, not the aggregation mechanism.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is correct for a specific slice of centralized logging because an organization trail can be enabled in the management account and automatically deliver a copy of all management events from every member account to a single S3 bucket in the central account. You can further validate file integrity and optionally stream those events to CloudWatch Logs or an external SIEM. However, it captures only AWS API activity, not application or network logs, so it complements rather than replaces CloudWatch Logs.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.