SCS-C02 Security Logging and Monitoring Practice Question
A Security Engineer is troubleshooting why AWS CloudTrail is not delivering logs to an S3 bucket. The bucket policy allows CloudTrail access. What is a likely cause of the issue?
⚠ Common exam trap
Candidates often assume the S3 bucket policy is the only authorization layer, overlooking that KMS key policies act as an independent permission boundary when SSE-KMS is used, leading them to choose incorrect options like cross-region or lifecycle issues.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The S3 bucket uses SSE-KMS and the key policy does not grant CloudTrail permission
When an S3 bucket uses SSE-KMS (Server-Side Encryption with AWS KMS), CloudTrail must have explicit permissions in the KMS key policy to decrypt the key and encrypt log files. Even if the S3 bucket policy grants CloudTrail access, the KMS key policy is a separate authorization layer; without a statement allowing CloudTrail to use the kms:GenerateDataKey and kms:Decrypt actions, log delivery will fail silently or with access denied errors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The S3 bucket uses SSE-KMS and the key policy does not grant CloudTrail permission
Why this is correct
CloudTrail requires explicit kms:GenerateDataKey and kms:Decrypt permissions on the customer managed KMS key used for SSE-KMS encryption of the S3 bucket. If the key policy grants these actions only to the bucket owner or other principals, CloudTrail's delivery role is denied and PutObject calls fail with an access denied error. This is a common cause of CloudTrail logs not appearing while the trail itself remains active.
- ✗
The S3 bucket has a lifecycle policy that deletes objects too quickly
Why it's wrong here
A lifecycle policy that transitions or expires objects operates asynchronously after objects are written; it does not block CloudTrail from delivering log files in real time. Even an aggressive expiration rule would only remove objects minutes or days later, after the delivery attempt has already succeeded. Therefore, lifecycle configuration cannot prevent CloudTrail from writing the initial log files.
- ✗
CloudTrail is not enabled in the region
Why it's wrong here
CloudTrail trails are regional resources; if CloudTrail is not enabled in the region where the trail is configured, no trail would exist to deliver logs. Because the CloudTrail console and APIs only show trails that were successfully created in a region, a missing trail indicates a creation failure or no configuration, not a delivery failure of an existing trail. This option cannot explain why an already created trail stops delivering logs.
- ✗
The S3 bucket is in a different region than the trail
Why it's wrong here
CloudTrail explicitly supports delivering logs to an S3 bucket in a different region than the trail, as long as the bucket policy allows cross-account or cross-region writes. When you create a trail, CloudTrail adds the necessary bucket policy statements to deliver to any valid S3 bucket regardless of region. Therefore, the bucket being in a different region does not inherently prevent log delivery and is not a valid cause of the issue.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.