SCS-C02 Security Logging and Monitoring Practice Question
Which TWO AWS services can be used to monitor and detect unauthorized changes to Amazon S3 bucket policies? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse Amazon GuardDuty's ability to analyze CloudTrail logs for threat detection with direct monitoring of S3 policy changes, but GuardDuty does not have built-in rules to detect unauthorized policy modifications; it focuses on anomalous behavior like unusual API patterns, not specific resource-level changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is correct because it records all API calls made to Amazon S3, including changes to bucket policies (e.g., PutBucketPolicy, DeleteBucketPolicy). By enabling CloudTrail on the S3 bucket or using a trail that logs data events for S3, you can monitor and detect unauthorized policy modifications in near real-time through the CloudTrail event history or by delivering logs to Amazon CloudWatch Logs for further analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail records management events in your account, including the PutBucketPolicy API call that modifies an S3 bucket policy. This gives you a complete, auditable history of who made the change, from which IP address, and when, making it a primary service for detecting and investigating policy changes.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that analyzes streams of data such as DNS queries, VPC Flow Logs, and CloudTrail management events to identify malicious activity like unauthorized access or crypto mining. It does not natively track or report on S3 bucket policy modifications as a compliance or change-management function, and it focuses on anomalies indicating threats, not on configuration drift or policy audit.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs stores and aggregates log output from applications and AWS services, allowing you to search and create metric filters and alarms on textual patterns. However, detecting an S3 bucket policy change would require you to separately send CloudTrail events into CloudWatch Logs and build a custom filter; CloudWatch Logs itself does not actively monitor or detect bucket policy modifications natively.
- ✓
AWS Config
Why this is correct
AWS Config continuously records and evaluates configuration changes to AWS resources, including S3 buckets and their bucket policies. It maintains a configuration timeline and can trigger rules to flag noncompliant policies, giving you the ability to detect and alert on any alteration to an S3 bucket policy as part of its managed configuration tracking.
- ✗
Amazon VPC Flow Logs
Why it's wrong here
Amazon VPC Flow Logs capture metadata about IP traffic flowing to and from network interfaces in your VPC, such as source and destination addresses, ports, and packet counts. They provide visibility into network-level activity but do not capture API calls or management operations like PutBucketPolicy, so they cannot be used to detect S3 bucket policy changes.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.