SCS-C02 Data Protection Practice Question
Network Topology
Refer to the exhibit. A security engineer is reviewing the CloudWatch Logs configuration for a Lambda function. The log group is encrypted with a customer managed key. The engineer needs to ensure that only the Lambda service can write logs to this log group and that only a specific IAM role can read logs. Which additional configuration is required?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a condition to the KMS key policy that uses kms:ViaService to restrict encryption/decryption to logs.amazonaws.com and a condition that the Lambda function is the source
To ensure only the Lambda service can write logs and only a specific IAM role can read logs, you need to use KMS key policy conditions. The key policy should include a condition that allows CloudWatch Logs to use the key for encryption/decryption only when the request originates from the Lambda service (using kms:ViaService condition). Additionally, you can restrict read access by specifying the IAM role in the key policy. Option A is incorrect because resource-based policies on log groups cannot restrict write access to Lambda only; they are typically used for cross-account access. Option B is incorrect because S3 bucket policies are not applicable to CloudWatch Logs. Option C is incorrect because you cannot assign an IAM role to a log group; IAM roles are assumed by entities, not assigned to resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach a resource-based policy to the log group that allows only the Lambda service to write logs
Why it's wrong here
CloudWatch Logs resource-based policies (PutResourcePolicy) are meant to grant cross-account or cross-service access to a log group, such as allowing Kinesis Data Firehose or OpenSearch Ingestion to deliver to it. They cannot be scoped to allow only the Lambda service as a writer, because Lambda does not authenticate as a service principal when writing to a log group; it uses its execution role's logs:CreateLogStream and logs:PutLogEvents permissions. Even if such a policy existed, it would not address the KMS key permissions required to decrypt the log group's encryption key, so it would not fix the underlying issue.
- ✗
Create an S3 bucket policy to allow only Lambda to write to the log group
Why it's wrong here
An S3 bucket policy is a resource-based policy attached to an S3 bucket and only controls access to objects in that bucket. It has no effect on CloudWatch Logs or on a KMS key used to encrypt a log group, because the log group is a separate service with its own auth model and KMS grants. Therefore, creating an S3 bucket policy that 'allows only Lambda to write to the log group' is fundamentally misplaced and cannot influence either CloudWatch Logs write permissions or the KMS key policy needed for decryption.
- ✗
Assign an IAM role to the log group that has permission to write logs
Why it's wrong here
IAM roles are assumed by identities or AWS services to obtain temporary credentials; a CloudWatch Logs log group is not an identity and cannot assume or be assigned an IAM role. The Lambda function's execution role is what carries the logs:PutLogEvents permission, but that applies to the principal writing the logs, not to the log group itself. Moreover, when the log group is KMS-encrypted, the Lambda execution role must also be allowed by the KMS key policy to use the key, so the fix must be made in the key policy rather than trying to attach an IAM role to the log group.
- ✓
Add a condition to the KMS key policy that uses kms:ViaService to restrict encryption/decryption to logs.amazonaws.com and a condition that the Lambda function is the source
Why this is correct
This is correct because the KMS key policy is the authoritative control for who can use the customer-managed key, and CloudWatch Logs calls KMS on behalf of the Lambda function when encrypting/decrypting log data. Adding a statement with Principal as logs.amazonaws.com and a condition using kms:ViaService logs.<region>.amazonaws.com restricts the key's use to calls that come through the CloudWatch Logs service endpoint. To ensure the request is tied to the specific Lambda function, you would also include a condition such as aws:SourceArn matching the Lambda function ARN or an EncryptionContext condition on the log group ARN, so the key cannot be used for unrelated log groups or services.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.