Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A Security Engineer is troubleshooting why AWS CloudTrail is not delivering logs to an S3 bucket. The bucket policy allows CloudTrail access. What is a likely cause of the issue?

⚠ Common exam trap

Candidates often assume the S3 bucket policy is the only authorization layer, overlooking that KMS key policies act as an independent permission boundary when SSE-KMS is used, leading them to choose incorrect options like cross-region or lifecycle issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The S3 bucket uses SSE-KMS and the key policy does not grant CloudTrail permission

When an S3 bucket uses SSE-KMS (Server-Side Encryption with AWS KMS), CloudTrail must have explicit permissions in the KMS key policy to decrypt the key and encrypt log files. Even if the S3 bucket policy grants CloudTrail access, the KMS key policy is a separate authorization layer; without a statement allowing CloudTrail to use the kms:GenerateDataKey and kms:Decrypt actions, log delivery will fail silently or with access denied errors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The S3 bucket uses SSE-KMS and the key policy does not grant CloudTrail permission

    Why this is correct

    CloudTrail requires explicit kms:GenerateDataKey and kms:Decrypt permissions on the customer managed KMS key used for SSE-KMS encryption of the S3 bucket. If the key policy grants these actions only to the bucket owner or other principals, CloudTrail's delivery role is denied and PutObject calls fail with an access denied error. This is a common cause of CloudTrail logs not appearing while the trail itself remains active.

  • ✗

    The S3 bucket has a lifecycle policy that deletes objects too quickly

    Why it's wrong here

    A lifecycle policy that transitions or expires objects operates asynchronously after objects are written; it does not block CloudTrail from delivering log files in real time. Even an aggressive expiration rule would only remove objects minutes or days later, after the delivery attempt has already succeeded. Therefore, lifecycle configuration cannot prevent CloudTrail from writing the initial log files.

  • ✗

    CloudTrail is not enabled in the region

    Why it's wrong here

    CloudTrail trails are regional resources; if CloudTrail is not enabled in the region where the trail is configured, no trail would exist to deliver logs. Because the CloudTrail console and APIs only show trails that were successfully created in a region, a missing trail indicates a creation failure or no configuration, not a delivery failure of an existing trail. This option cannot explain why an already created trail stops delivering logs.

  • ✗

    The S3 bucket is in a different region than the trail

    Why it's wrong here

    CloudTrail explicitly supports delivering logs to an S3 bucket in a different region than the trail, as long as the bucket policy allows cross-account or cross-region writes. When you create a trail, CloudTrail adds the necessary bucket policy statements to deliver to any valid S3 bucket regardless of region. Therefore, the bucket being in a different region does not inherently prevent log delivery and is not a valid cause of the issue.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.