SCS-C02 Security Logging and Monitoring Practice Question
A security engineer needs to ensure that all S3 buckets in an AWS account have server access logging enabled. Which AWS service should be used to continuously monitor for compliance?
⚠ Common exam trap
Many exam-takers confuse AWS Config with AWS CloudTrail, mistakenly thinking that CloudTrail's logging of API calls can be used to continuously monitor compliance, but CloudTrail only records events and does not evaluate the current state of resources against a desired configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it provides continuous monitoring and evaluation of your AWS resource configurations against desired policies. You can create an AWS Config rule, such as the managed rule 's3-bucket-server-access-logging-enabled', which will automatically check all S3 buckets in your account and report any that do not have server access logging enabled, flagging them as noncompliant. This allows for ongoing, automated compliance auditing without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config
Why this is correct
AWS Config is the correct choice because it is a configuration assessment service that continuously records S3 bucket configurations and evaluates them against managed rules such as s3-bucket-logging-enabled. When server access logging is disabled, the rule marks the bucket as noncompliant, and you can automate remediation with SSM documents or custom Lambda functions. AWS Config provides a compliance history, so you can see exactly when a bucket fell out of compliance, which is essential for audit evidence.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service, not a configuration compliance tool. It ingests AWS CloudTrail management events, VPC Flow Logs, and DNS query logs to generate findings for suspicious activity such as credential exfiltration, cryptocurrency mining, or anomalous API calls. While GuardDuty might flag an S3 bucket with public read access if it attracts anomalous access patterns, it has no awareness of whether server access logging is enabled on a bucket, and it does not evaluate bucket configurations against compliance rules.
- ✗
AWS IAM Access Analyzer
Why it's wrong here
AWS IAM Access Analyzer is designed to identify resource-based policies that grant access to external principals, such as a bucket policy allowing cross-account or public access. It generates findings for S3 buckets that are shared outside your AWS account, which helps you catch unintended exposure. However, it does not inspect bucket logging settings; a bucket could have a perfectly private policy yet have server access logging disabled, and IAM Access Analyzer would not flag that as an issue because it only analyzes policy accessibility, not operational audit configurations.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API activity, including S3 management events like CreateBucket and PutBucketLogging, as well as data events for object-level operations if explicitly enabled. A CloudTrail trail can show when someone disabled logging on a bucket, but it does not continuously evaluate the live configuration of a bucket; it is a chronological log of actions, not a compliance checker. Furthermore, S3 server access logs are distinct from CloudTrail—server access logs capture detailed request records for object access, while CloudTrail captures API calls—so CloudTrail cannot substitute for the s3-bucket-logging-enabled AWS Config rule.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.