Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

Network Topology
aws cloudtrail get-event-selectorstrail-name my-trailRefer to the exhibit."EventSelectors": ["ReadWriteType": "All","IncludeManagementEvents": true,"DataResources": ["Type": "AWS::S3::Object","Values": ["arn:aws:s3:::my-bucket/logs/"]],"ExcludeManagementEventSources": []"AdvancedEventSelectors": []

A security engineer needs to ensure that all S3 object-level API calls (e.g., GetObject, PutObject) on the bucket 'my-bucket' are logged. The current CloudTrail configuration is as shown in the exhibit. What change should the engineer make?

⚠ Common exam trap

Many exam-takers think the bucket ARN without a trailing slash is sufficient for object-level logging, not realizing that the trailing slash is required to match all objects within the bucket, a nuance that CloudTrail documentation explicitly states.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the data resource value to 'arn:aws:s3:::my-bucket/' to cover all objects.

To log all S3 object-level API calls (GetObject, PutObject, etc.) on the bucket 'my-bucket', the DataResources value must specify the bucket's ARN with a trailing slash (arn:aws:s3:::my-bucket/) to indicate all objects within the bucket. Without the trailing slash, CloudTrail interprets the ARN as referring to the bucket itself, not its objects, and thus object-level events are not captured. The trailing slash ensures the selector applies to all object keys under that bucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove the DataResources section and add an AdvancedEventSelector for S3.

    Why it's wrong here

    Removing the DataResources section and adding an AdvancedEventSelector for S3 is incorrect because the trail is already configured to log S3 data events through DataResources. The problem is the syntax of the ARN, not the selector type. AdvancedEventSelectors are used for more granular filtering of management events or for custom event patterns, but they do not fix the issue of the DataResource's missing trailing slash. Keeping the DataResources configuration and correcting the ARN is the appropriate solution.

  • ✗

    Change the bucket ARN to 'arn:aws:s3:::my-bucket' without a trailing slash.

    Why it's wrong here

    Changing the bucket ARN to 'arn:aws:s3:::my-bucket' without a trailing slash would still fail to capture object-level events. In CloudTrail, a bucket ARN without the slash identifies the bucket resource itself, which only matches operations such as CreateBucket or DeleteBucket. To capture events for all objects within the bucket, the DataResource must include a trailing slash after the bucket name, indicating the root prefix that covers every object. Thus, this change does not address the root cause.

  • ✗

    Enable management events by setting IncludeManagementEvents to true.

    Why it's wrong here

    Setting IncludeManagementEvents to true is unnecessary because management events are already being recorded by the trail, and the issue concerns S3 object-level data events. Object-level events (e.g., GetObject, PutObject) are classified as data events, not management events. Enabling or keeping management events enabled will not resolve the missing object-level logging. The defect lies in the DataResource value, which fails to target the bucket's objects due to the missing trailing slash.

  • ✓

    Change the data resource value to 'arn:aws:s3:::my-bucket/' to cover all objects.

    Why this is correct

    Changing the data resource value to 'arn:aws:s3:::my-bucket/' correctly covers all objects within the bucket. In CloudTrail's DataResource configuration for S3, the ARN must specify a prefix; a trailing slash after the bucket name represents the root prefix, meaning all objects inside that bucket. Without the slash, CloudTrail does not match object-level operations. This is the standard pattern for logging all S3 data events for a single bucket.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.