SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is investigating a potential data breach. The engineer needs to identify which IAM user accessed a specific S3 object and when. Which AWS service should the engineer use?
⚠ Common exam trap
Many candidates confuse S3 server access logs (which show HTTP-level requests but lack IAM user identity) with CloudTrail (which captures the full IAM user context via the AWS API), leading them to incorrectly select Amazon S3 server access logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records API activity for all AWS services, including S3 object-level operations such as GetObject, PutObject, and DeleteObject. By enabling data events on the specific S3 bucket, CloudTrail logs the IAM user, source IP, timestamp, and the exact object key accessed, providing the precise identity and time needed for breach investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config is an incorrect choice because it is a resource inventory and compliance service that records configuration item changes (e.g., bucket policies, encryption settings, lifecycle rules) over time, not object-level access events. It does not capture who called GetObject or PutObject against a specific S3 key, nor does it record the IAM user's identity or timestamp of an access attempt. While Config rules could alert on a misconfigured bucket policy that might have enabled the breach, they cannot forensically trace which principal accessed the compromised object, making it inadequate for this investigation.
- ✗
Amazon S3 server access logs
Why it's wrong here
S3 server access logs are incorrect because while they do record each request made to a bucket, including object key, source IP, and timestamp, the 'requester' field frequently does not resolve to an IAM user identity. For requests made with temporary credentials from an assumed role, or for anonymous requests, the requester field may be 'Anonymous' or an account ID and role session name, not the specific IAM user. Additionally, server access logs are delivered on a best-effort basis (often delayed by several hours) and require an additional bucket for log storage, so they lack the reliable, low-latency, user-identity mapping that CloudTrail's data events provide.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the correct answer because it is the only service that records API activity as data events for S3, and by default (when data events are enabled) it captures the exact IAM user principal, source IP address, user agent, request parameters, and timestamp for actions like GetObject and PutObject. This enables the security engineer to create a complete audit trail of who accessed a specific S3 object and when, which is precisely what is needed in a breach investigation. CloudTrail also integrates with CloudWatch Logs for alerting and can deliver to a separate S3 bucket or a security data lake, but its core value here is the user-level accountability it provides for object-level operations.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
CloudWatch Logs stores application and system log data, not IAM user-level API actions against specific S3 objects. The engineer needs to identify which IAM user accessed a particular S3 object and when—this requires AWS CloudTrail’s data event logging for S3, which captures user identity, source IP, and timestamp per object operation. CloudWatch Logs is tempting because it aggregates logs from various sources, and would be correct if the engineer needed to monitor application-level errors or metric filters on existing log streams, but it lacks the granular, user-specific S3 data event records that CloudTrail provides.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.