Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to ensure that all objects uploaded to an S3 bucket are automatically scanned for malware before being made accessible to users. Which solution is MOST appropriate?

⚠ Common exam trap

Many candidates confuse logging/monitoring services (VPC Flow Logs, CloudWatch Logs) with active security controls, failing to recognize that malware scanning requires compute-based content inspection, not just metadata or access logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use S3 event notifications to invoke an AWS Lambda function that runs a malware scanning solution.

S3 event notifications can be configured to trigger an AWS Lambda function upon object creation, allowing the Lambda function to run a malware scanning solution (e.g., using ClamAV or an AWS Marketplace partner) before the object is made accessible. This serverless approach ensures automated, near-real-time scanning without manual intervention, and the Lambda function can quarantine or delete malicious objects by adjusting S3 bucket policies or object ACLs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable VPC Flow Logs to capture all access to the bucket.

    Why it's wrong here

    VPC Flow Logs capture network-level metadata such as IP addresses, ports, and protocols for traffic traversing a VPC, not S3 object contents or API operations. Because S3 is a managed internet service, flow logs cannot reveal object-level events like GetObject or PutObject, nor can they inspect uploaded files for malware. Thus this option fails to meet the requirement of scanning every uploaded object.

  • ✗

    Enable S3 Object Lock on the bucket.

    Why it's wrong here

    S3 Object Lock enforces a write-once-read-many (WORM) model, which prevents objects from being deleted or overwritten for a specified retention period or legal hold. It is designed for regulatory compliance and protecting data integrity, not for analyzing file contents. Enabling Object Lock does not invoke any inspection of uploaded objects, so malicious payloads would remain undetected and accessible.

  • ✗

    Configure Amazon CloudWatch Logs to monitor S3 access logs.

    Why it's wrong here

    S3 server access logs record request metadata such as the requester, timestamp, operation, bucket name, and response status, but never include the object's data payload. Sending these logs to CloudWatch Logs allows you to monitor for suspicious access patterns or operational issues, but it cannot scan files for malware. Therefore this approach only provides visibility into who did what, not whether uploaded content is malicious.

  • ✓

    Use S3 event notifications to invoke an AWS Lambda function that runs a malware scanning solution.

    Why this is correct

    S3 event notifications can be configured to publish PUT or POST events to AWS Lambda, triggering a function each time an object is uploaded. The Lambda function can then use GetObject to retrieve the object and run a malware scanning engine such as ClamAV, applying tags or deleting/quarantining the object based on the scan verdict. This serverless, event-driven pattern provides immediate, per-object inspection and scales automatically with upload volume.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.