Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer is designing a centralized logging solution for multiple AWS accounts. Which TWO services should be used to aggregate logs from all accounts into a single account? (Choose TWO.)

⚠ Common exam trap

Test-takers frequently confuse log destinations (like S3) with log aggregation services, failing to recognize that S3 is a passive storage target and does not actively collect or aggregate logs from multiple accounts without the orchestration provided by CloudWatch Logs or CloudTrail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Logs

Amazon CloudWatch Logs can receive log data from multiple AWS accounts via cross-account subscription filters, allowing a centralized logging account to aggregate logs from all source accounts. AWS CloudTrail can be configured to deliver trail logs from multiple accounts to a single S3 bucket in a central account, enabling consolidated audit logging. Together, these two services provide a comprehensive centralized logging solution for multi-account environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records configuration state and changes for AWS resources, and it can aggregate that configuration and compliance data across accounts using an aggregator. It does not collect runtime application logs, security findings, or user activity logs, which are the typical inputs of a centralized logging solution. For log aggregation you need a pipeline that streams log events, not a configuration recorder.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata for network interfaces and can be published to Amazon S3 or CloudWatch Logs, but they are not delivered directly into a central account. To centralize them you would need additional steps such as S3 bucket replication, cross-account bucket policies, or a CloudWatch Logs subscription filter to forward them. They are therefore a log source that requires extra architecture, not a standalone centralized log aggregation service.

  • ✓

    Amazon CloudWatch Logs

    Why this is correct

    Amazon CloudWatch Logs is correct because you can create a cross-account destination in a central account—for example, a Kinesis Data Streams stream or an Amazon OpenSearch Service cluster—and attach a subscription filter in each source account's log group to stream log events to that destination. The CloudWatch Logs destination resource holds the ARN of the central resource and an IAM role that grants the source account permission to send data. This natively supports the real-time, centralized log collection that the scenario requires.

  • ✗

    Amazon S3

    Why it's wrong here

    Amazon S3 is an object storage service that can act as a durable landing zone for logs, but it does not provide the aggregation logic needed to collect logs from multiple sources and accounts. Services like CloudTrail and VPC Flow Logs can deliver files into a central bucket, and S3 Replication can copy objects, but S3 cannot subscribe to CloudWatch log events or filter/forward them. In a centralized logging design, S3 should be the final repository, not the aggregation mechanism.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is correct for a specific slice of centralized logging because an organization trail can be enabled in the management account and automatically deliver a copy of all management events from every member account to a single S3 bucket in the central account. You can further validate file integrity and optionally stream those events to CloudWatch Logs or an external SIEM. However, it captures only AWS API activity, not application or network logs, so it complements rather than replaces CloudWatch Logs.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.