Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

Which THREE are best practices for securing AWS CloudTrail log files? (Choose three.)

⚠ Common exam trap

A common mix-up: candidates confuse operational convenience (e.g., same-region delivery or short retention) with security best practices, forgetting that security requires cross-region resilience and long-term retention for auditability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict access to the S3 bucket using a bucket policy that requires MFA and encryption.

Restricting access to the S3 bucket with a bucket policy that requires MFA (Multi-Factor Authentication) and encryption (e.g., aws:MultiFactorAuthPresent and aws:SecureTransport conditions) ensures that only authenticated and authorized users can access CloudTrail logs, and that data is encrypted in transit. This prevents unauthorized deletion or modification of log files, which is critical for maintaining an immutable audit trail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Restrict access to the S3 bucket using a bucket policy that requires MFA and encryption.

    Why this is correct

    Restricting access to the S3 bucket with a bucket policy that includes the aws:MultiFactorAuthPresent condition ensures that every request requires MFA authentication, significantly reducing the risk of unauthorized log access even if a user's long-term credentials are compromised. Adding an encryption enforcement condition, such as requiring TLS (aws:SecureTransport) or mandatory SSE-KMS headers, further protects the logs in transit and at rest. This layered access control is a best practice because it hardens the audit trail against both external attacks and accidental exposure.

  • ✓

    Enable CloudTrail log file integrity validation.

    Why this is correct

    CloudTrail log file integrity validation uses cryptographically signed digest files that contain hash values for each delivered log file, allowing you to later verify that the logs have not been modified, deleted, or tampered with after delivery. AWS publishes the public key used for signature verification, so you can independently confirm the authenticity of every log file. This feature is essential for maintaining the evidentiary value of audit logs and detecting unauthorized changes, making it a core security best practice.

  • ✓

    Enable server-side encryption (SSE) for the S3 bucket.

    Why this is correct

    Enabling server-side encryption (SSE) for the S3 bucket encrypts CloudTrail log files at rest, with options including SSE-S3 for S3-managed keys or SSE-KMS for customer-managed AWS KMS keys. Using SSE-KMS gives you granular control over key rotation and access, because an IAM or KMS policy must grant both s3:GetObject and kms:Decrypt permissions to anyone reading the logs. This creates a second layer of defense so that even if S3 permissions are misconfigured, the log content remains unreadable without the encryption key.

  • ✗

    Deliver logs to an S3 bucket in the same region as the trail.

    Why it's wrong here

    Delivering CloudTrail logs to an S3 bucket in the same region as the trail is incorrect because best practice is to configure cross-region delivery to a centralized bucket in a different AWS region, ensuring the logs remain available if the trail's region suffers an outage or disaster. Same-region delivery introduces a single point of failure and defeats the purpose of maintaining durable, independent audit records. Cross-region aggregation also simplifies compliance by consolidating logs from all regions into one controlled repository.

  • ✗

    Set a lifecycle policy to delete logs after 30 days.

    Why it's wrong here

    Setting an S3 lifecycle policy to delete CloudTrail logs after 30 days is not a best practice because regulations and internal security policies—such as PCI DSS, HIPAA, and SOC 2—commonly require retaining audit logs for at least one year, if not longer. Deleting logs prematurely removes the ability to perform historical investigations or threat hunting, and may result in compliance violations. Instead, best practice is to transition older logs to Amazon S3 Glacier or Glacier Deep Archive using lifecycle rules while preserving them for the mandated retention period.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.