SCS-C02 Security Logging and Monitoring Practice Question
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": "cloudtrail.amazonaws.com"
},
"Action": "s3:PutObject",
"Resource": "arn:aws:s3:::my-trail-bucket/AWSLogs/*"
}
]
}Refer to the exhibit. A security engineer configured this S3 bucket policy to allow CloudTrail to deliver logs. However, logs are not being delivered. What is the MOST likely reason?
⚠ Common exam trap
The trap here is that candidates focus on the obvious s3:PutObject action and overlook the prerequisite s3:GetBucketAcl permission, which CloudTrail requires for its initial access validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy is missing s3:GetBucketAcl permission for CloudTrail.
CloudTrail requires the s3:GetBucketAcl permission on the S3 bucket to verify that the bucket policy grants the necessary access for log delivery. Without this permission, CloudTrail cannot confirm it has write access, and log delivery fails even if s3:PutObject is allowed. Option D correctly identifies this missing permission as the root cause.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Resource should be arn:aws:s3:::my-trail-bucket/*, not with AWSLogs prefix.
Why it's wrong here
Changing the resource to only the bucket root would break CloudTrail log delivery. CloudTrail stores logs under object keys that begin with the AWSLogs prefix, so the policy must target arn:aws:s3:::my-trail-bucket/AWSLogs/* (or a similar scoped key pattern). The bucket-root ARN alone fails to grant the s3:PutObject action because object-level actions require a resource that includes the object key path. The existing prefix is therefore correct and is also more restrictive than granting write access to the entire bucket.
- ✗
The Principal is set to a service, but must be an AWS account ID.
Why it's wrong here
This bucket policy is correct to use a service principal. CloudTrail operates as the AWS service 'cloudtrail.amazonaws.com' when delivering logs, and IAM bucket policies support service principals for that purpose. Substituting an AWS account ID would be wrong because CloudTrail does not run as a specific account root user, and it would defeat cross-account delivery in organizations where the trail bucket is in a different account. The IAM principal type in this statement—Service, not AWS—is exactly what AWS documentation prescribes for CloudTrail bucket policies.
- ✗
The Action should be s3:GetObject, not s3:PutObject.
Why it's wrong here
Replacing s3:PutObject with s3:GetObject would invert the required permission and prevent CloudTrail from writing any log files. CloudTrail needs PutObject to upload the log objects it creates in the bucket; GetObject is a read operation that CloudTrail never calls during its normal delivery path. The action in the policy must also be exactly s3:PutObject (not s3:Put* or s3:GetObject) to satisfy CloudTrail's pre-flight permission checks. Therefore, keeping PutObject is necessary for successful log delivery.
- ✓
The policy is missing s3:GetBucketAcl permission for CloudTrail.
Why this is correct
The missing permission is s3:GetBucketAcl, and without it CloudTrail will reject the bucket even though PutObject is allowed. Before writing its first log, CloudTrail calls GetBucketAcl on the destination bucket to confirm the bucket's owner, and the bucket policy must explicitly grant that action to the cloudtrail service principal. If the bucket ACL check fails, CloudTrail returns an error such as 'bucket does not exist or bucket ACL does not allow access' and log delivery halts. This permission is a separate, required statement from the object-write permission.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.