Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A security engineer needs to ensure that all S3 buckets in an AWS account have server access logging enabled. Which AWS service should be used to continuously monitor for compliance?

⚠ Common exam trap

Many exam-takers confuse AWS Config with AWS CloudTrail, mistakenly thinking that CloudTrail's logging of API calls can be used to continuously monitor compliance, but CloudTrail only records events and does not evaluate the current state of resources against a desired configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config is the correct service because it provides continuous monitoring and evaluation of your AWS resource configurations against desired policies. You can create an AWS Config rule, such as the managed rule 's3-bucket-server-access-logging-enabled', which will automatically check all S3 buckets in your account and report any that do not have server access logging enabled, flagging them as noncompliant. This allows for ongoing, automated compliance auditing without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Config

    Why this is correct

    AWS Config is the correct choice because it is a configuration assessment service that continuously records S3 bucket configurations and evaluates them against managed rules such as s3-bucket-logging-enabled. When server access logging is disabled, the rule marks the bucket as noncompliant, and you can automate remediation with SSM documents or custom Lambda functions. AWS Config provides a compliance history, so you can see exactly when a bucket fell out of compliance, which is essential for audit evidence.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service, not a configuration compliance tool. It ingests AWS CloudTrail management events, VPC Flow Logs, and DNS query logs to generate findings for suspicious activity such as credential exfiltration, cryptocurrency mining, or anomalous API calls. While GuardDuty might flag an S3 bucket with public read access if it attracts anomalous access patterns, it has no awareness of whether server access logging is enabled on a bucket, and it does not evaluate bucket configurations against compliance rules.

  • ✗

    AWS IAM Access Analyzer

    Why it's wrong here

    AWS IAM Access Analyzer is designed to identify resource-based policies that grant access to external principals, such as a bucket policy allowing cross-account or public access. It generates findings for S3 buckets that are shared outside your AWS account, which helps you catch unintended exposure. However, it does not inspect bucket logging settings; a bucket could have a perfectly private policy yet have server access logging disabled, and IAM Access Analyzer would not flag that as an issue because it only analyzes policy accessibility, not operational audit configurations.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity, including S3 management events like CreateBucket and PutBucketLogging, as well as data events for object-level operations if explicitly enabled. A CloudTrail trail can show when someone disabled logging on a bucket, but it does not continuously evaluate the live configuration of a bucket; it is a chronological log of actions, not a compliance checker. Furthermore, S3 server access logs are distinct from CloudTrail—server access logs capture detailed request records for object access, while CloudTrail captures API calls—so CloudTrail cannot substitute for the s3-bucket-logging-enabled AWS Config rule.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.