Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer is troubleshooting an issue where CloudTrail is not delivering logs to an S3 bucket. The bucket policy appears correct. Which TWO additional steps should the engineer take to diagnose the issue? (Choose TWO.)

⚠ Common exam trap

Watch out — candidates often assume CloudTrail uses an IAM role for S3 access (like many other AWS services), but CloudTrail relies solely on a resource-based bucket policy, so creating an IAM role (Option C) is unnecessary and incorrect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the S3 bucket exists and is in the correct region.

If the S3 bucket does not exist or is in a different region, CloudTrail cannot deliver log files to it. CloudTrail requires the bucket to be in the same region as the trail (for a single-region trail) or in the designated bucket region for a multi-region trail. Verifying the bucket's existence and region ensures the delivery path is valid. Option E is correct because the CloudTrail configuration in the AWS Management Console displays error messages related to delivery failures, such as bucket policy issues or permission errors. Reviewing this console can provide immediate insight into why logs are not being delivered, without needing to check other logs manually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Verify that the S3 bucket exists and is in the correct region.

    Why this is correct

    CloudTrail can only write log files to an S3 bucket that already exists and is located in the same AWS Region as the trail. If the bucket was accidentally deleted, renamed, or created in another Region, every delivery attempt fails, and the trail's status shows a delivery error. Confirming this prerequisite is therefore the correct first troubleshooting step, because no policy or role change can compensate for a missing or misregioned destination.

  • ✗

    Check CloudWatch Logs for CloudTrail errors.

    Why it's wrong here

    CloudTrail can be configured to stream events to an Amazon CloudWatch Logs log group for metric filters and alarm-based monitoring, but S3 delivery errors are not written to that log stream. The console Trail Details pane and CloudWatch metrics for CloudTrail delivery are the authoritative sources for S3 delivery failures. Examining CloudWatch Logs for 'CloudTrail errors' would not reveal whether the bucket is missing or misregioned, so this diagnostic step is not applicable.

  • ✗

    Create an IAM role for CloudTrail with S3 write permissions.

    Why it's wrong here

    CloudTrail does not need an IAM role to write logs to an S3 bucket; it authenticates as the cloudtrail.amazonaws.com service principal, and the bucket must grant write permission through a resource-based bucket policy. An IAM role is required only when CloudTrail delivers events to CloudWatch Logs and must assume that role to create log groups and log streams. Creating an IAM role with S3 write permissions would neither fix a nonexistent bucket nor grant the bucket policy permissions CloudTrail actually uses.

  • ✗

    Enable S3 server access logging on the bucket.

    Why it's wrong here

    S3 server access logging records detailed request-level information about every API call made to the destination bucket, which is useful for post-hoc compliance and audit analysis once logs are arriving. It does not, however, trigger, enable, or repair CloudTrail delivery, and it cannot fix a bucket that is missing or in the wrong Region. Enabling it would only add another place to look after CloudTrail delivery is already working, not diagnose why it is failing.

  • ✓

    Review the CloudTrail configuration in the AWS Management Console for error messages.

    Why this is correct

    The CloudTrail console is a legitimate place to start because the Trails page shows the current delivery status and any associated error messages, such as 'S3 bucket does not exist'. If an error is displayed, it usually points directly to the underlying requirement, namely an existing, correctly Regioned destination bucket. Reviewing these console errors can quickly confirm or exclude the bucket configuration issue, making this a valid diagnostic step for this failure.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.