Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to ensure that all API activity in an AWS account is logged and that the logs are retained for 10 years for compliance. The engineer enables AWS CloudTrail with a multi-Region trail and delivers logs to an Amazon S3 bucket. The engineer must prevent any user, including administrators, from deleting or altering the logs during the retention period. Which solution meets these requirements?

⚠ Common exam trap

The trap here is assuming that S3 Versioning or bucket policies alone provide immutability, but they can be bypassed by users with sufficient permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Object Lock in compliance mode on the S3 bucket with a retention period of 10 years.

S3 Object Lock in compliance mode provides immutable storage for a specified retention period, even preventing the root user from deleting objects. This is the only option that guarantees logs cannot be deleted or altered for 10 years. Other options either allow administrators to bypass protections or do not enforce retention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable S3 Object Lock in compliance mode on the S3 bucket with a retention period of 10 years.

    Why this is correct

    S3 Object Lock in compliance mode prevents any user, including the root user, from deleting or overwriting objects until the retention period expires. This satisfies the requirement for immutability for 10 years. The other options either do not prevent deletion by administrators or do not provide the required retention guarantee.

  • ✗

    Apply an S3 bucket policy that denies s3:DeleteObject and s3:PutObject for all principals except the CloudTrail service.

    Why it's wrong here

    A bucket policy can deny delete and put actions, but administrators with permissions to modify the bucket policy can remove the restriction. This does not provide immutable retention for 10 years. The policy also might block CloudTrail from writing logs if not carefully scoped, and it does not prevent root user actions.

  • ✗

    Configure AWS CloudTrail to use a customer-managed AWS KMS key to encrypt the logs and enable key rotation.

    Why it's wrong here

    Encrypting logs with a KMS key protects confidentiality but does not prevent deletion or alteration of the S3 objects. An administrator with KMS key permissions could still delete logs. Key rotation is for cryptographic hygiene, not immutability. This does not meet the retention requirement.

  • ✗

    Enable S3 Versioning and configure a lifecycle rule to transition objects to S3 Glacier Deep Archive after 30 days.

    Why it's wrong here

    S3 Versioning allows recovery of deleted objects but does not prevent permanent deletion if an administrator deletes all versions. Lifecycle transition to Glacier Deep Archive reduces cost but does not enforce immutability. This does not meet the requirement to prevent deletion or alteration by any user.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.