SCS-C02 Management and Security Governance Practice Question
A security engineer is responsible for ensuring that all API calls made in an AWS account are logged and that the logs are immutable for at least one year. The engineer must also ensure that any attempt to delete or modify the logs triggers an alert. Which solution meets these requirements?
⚠ Common exam trap
The trap here is assuming that S3 versioning with MFA delete provides immutability, when it only allows recovery and requires MFA for permanent deletion, not preventing modification attempts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with Object Lock in compliance mode for one year, and create an Amazon EventBridge rule to alert on DeleteObject or PutObject events for the bucket.
To achieve immutable logs for one year and alert on tampering, use CloudTrail with log file validation, S3 Object Lock in compliance mode to prevent deletion or modification, and EventBridge to detect and alert on DeleteObject or PutObject events for the bucket. This combination ensures logs cannot be altered and any attempt triggers an alert.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with versioning and MFA delete enabled, and create an Amazon EventBridge rule to alert on DeleteObject or PutObject events for the bucket.
Why it's wrong here
While CloudTrail with log file validation and S3 versioning with MFA delete provides immutability, using EventBridge to alert on DeleteObject or PutObject events for the bucket is not sufficient. EventBridge would need to monitor CloudTrail logs for those API calls, which could be tampered with if the logs are deleted. Additionally, MFA delete requires MFA to delete versions, but it does not prevent modification of the bucket policy or logging configuration.
- ✓
Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with Object Lock in compliance mode for one year, and create an Amazon EventBridge rule to alert on DeleteObject or PutObject events for the bucket.
Why this is correct
CloudTrail with log file validation ensures log integrity. S3 Object Lock in compliance mode prevents deletion or modification for the retention period, providing immutability for one year. An EventBridge rule that triggers on DeleteObject or PutObject events for the bucket will alert on any attempt to delete or modify the logs, meeting all requirements.
- ✗
Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with versioning and MFA delete enabled, and create an Amazon CloudWatch alarm on the CloudTrail metric for log file delivery failures.
Why it's wrong here
Versioning and MFA delete allow recovery of deleted logs but do not prevent modification or deletion attempts; they only require MFA for permanent deletion. A CloudWatch alarm on delivery failures does not alert on attempts to delete or modify logs. This solution does not provide immutable logs for one year or alert on tampering attempts.
- ✗
Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with Object Lock in compliance mode for one year, and create an Amazon CloudWatch alarm on the CloudTrail metric for log file delivery failures.
Why it's wrong here
Object Lock in compliance mode prevents deletion or modification for the retention period, which meets immutability. However, a CloudWatch alarm on log file delivery failures does not alert on attempts to delete or modify the logs; it only indicates when logs are not being delivered. The requirement is to alert on any attempt to delete or modify the logs, which requires monitoring for those specific API calls.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.