Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer needs to centrally aggregate AWS CloudTrail management events from all accounts in an AWS Organizations organization and retain them for 7 years in immutable storage. The engineer has already created an organization trail that delivers to a central S3 bucket in the security account. Which additional configuration is required to make the logs tamper-evident and to detect if any account attempts to disable CloudTrail?

⚠ Common exam trap

The trap here is assuming that S3 Versioning or MFA Delete alone provides immutability, when those only protect against deletion and do not prevent overwrites or prove log integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Object Lock in compliance mode on the central bucket and enable CloudTrail log file validation, then create an Amazon EventBridge rule for the CloudTrail StopLogging API call.

Immutability and tamper detection are two distinct controls. S3 Object Lock in compliance mode enforces WORM retention so logs cannot be altered or deleted for the retention period, and CloudTrail log file validation produces digest files that let you verify delivered logs were not modified. Because disabling a trail stops future delivery, an EventBridge rule matching the StopLogging event (and related trail APIs) is needed to alert the security team immediately.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable S3 Versioning and MFA Delete on the central bucket, then configure AWS Config to record the cloudtrail:StopLogging API as a configuration change.

    Why it's wrong here

    Versioning and MFA Delete protect against accidental or unauthorized deletion but do not prevent an object from being overwritten or provide a cryptographic integrity check on the log content itself, so they are weaker than Object Lock plus log file validation. AWS Config records resource configuration changes but does not directly alert on the API call, so detection is incomplete.

  • ✓

    Enable S3 Object Lock in compliance mode on the central bucket and enable CloudTrail log file validation, then create an Amazon EventBridge rule for the CloudTrail StopLogging API call.

    Why this is correct

    S3 Object Lock in compliance mode prevents deletion or overwrite of log objects for the retention period, satisfying the immutability requirement. CloudTrail log file validation adds a digest file so tampering with delivered logs is detectable. An EventBridge rule matching the StopLogging event (and other trail-modification APIs) provides the alerting on attempts to disable logging.

  • ✗

    Enable AWS CloudTrail Insights on the organization trail and configure an Amazon SNS topic to notify the security team when unusual API activity is detected.

    Why it's wrong here

    CloudTrail Insights detects anomalous write-management API call rates, not the specific act of disabling a trail, and it does not make the S3 objects immutable. SNS notification of Insights findings does not provide the required tamper-evidence or retention guarantee for a 7-year compliance obligation.

  • ✗

    Enable Amazon Macie on the central bucket to detect anomalous access and configure an S3 bucket policy that denies s3:DeleteObject to all principals except the CloudTrail service principal.

    Why it's wrong here

    Macie discovers and classifies sensitive data in S3; it is not designed to detect attempts to disable CloudTrail or to provide WORM retention. A bucket policy denying DeleteObject still permits overwrite of existing objects and does not satisfy a 7-year immutability requirement, and it does not address detection of the StopLogging API call.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.