SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is troubleshooting an issue where CloudTrail logs are not being delivered to the specified S3 bucket. The bucket policy allows CloudTrail to write objects. What is the MOST likely cause?
⚠ Common exam trap
The trap here is that candidates often overlook explicit deny statements in bucket policies, assuming that an allow statement alone is sufficient for CloudTrail log delivery, but AWS IAM policy evaluation always prioritizes explicit denies over allows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The S3 bucket has a bucket policy that denies access to the CloudTrail service principal.
The most likely cause is that the S3 bucket policy explicitly denies access to the CloudTrail service principal. Even if a bucket policy allows CloudTrail to write logs, an explicit deny statement overrides any allow, preventing log delivery. This is a common misconfiguration where a deny rule is inadvertently applied to the CloudTrail principal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The S3 bucket uses server-side encryption with customer-provided keys (SSE-C).
Why it's wrong here
SSE-C is a per-object encryption mode, not a bucket-level default, and it is not supported by CloudTrail for log delivery. CloudTrail automatically uses SSE-S3 for new buckets and can optionally use SSE-KMS, but it cannot supply the customer-provided key headers required for SSE-C. Even if an encryption mismatch occurred, it would surface as an S3 encryption error rather than an Access Denied caused by a bucket policy deny.
- ✓
The S3 bucket has a bucket policy that denies access to the CloudTrail service principal.
Why this is correct
An explicit Deny statement in the destination bucket policy that references the CloudTrail service principal (cloudtrail.amazonaws.com) will override any Allow that CloudTrail receives through its service role or resource-based policies. In AWS IAM policy evaluation, an explicit deny acts as an absolute veto, so CloudTrail's attempts to perform s3:PutObject and s3:GetBucketAcl fail with Access Denied. Because this would block delivery regardless of encryption, versioning, or account location, it is the likely root cause.
- ✗
The S3 bucket does not have versioning enabled.
Why it's wrong here
Versioning is an optional bucket property for CloudTrail log storage, not a prerequisite for writing new objects. When versioning is disabled, CloudTrail still successfully delivers log files; the only impact is that overwritten or deleted versions are not retained. Since a delivery failure would appear as an authorization or access error rather than a versioning-related error, the absence of versioning cannot explain the issue.
- ✗
The S3 bucket is in a different AWS account.
Why it's wrong here
CloudTrail explicitly supports delivering logs to an S3 bucket in a different AWS account, provided the bucket policy includes the appropriate cross-account Allow statements for the CloudTrail service principal and the expected AWSLogs prefix. A remote bucket alone does not prevent delivery; only a missing or misconfigured resource policy would. Therefore, the bucket's account location is not inherently the cause, and the contents of the bucket policy are what should be examined.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.