Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

Which TWO AWS services can be used to monitor and detect unauthorized changes to Amazon S3 bucket policies? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse Amazon GuardDuty's ability to analyze CloudTrail logs for threat detection with direct monitoring of S3 policy changes, but GuardDuty does not have built-in rules to detect unauthorized policy modifications; it focuses on anomalous behavior like unusual API patterns, not specific resource-level changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is correct because it records all API calls made to Amazon S3, including changes to bucket policies (e.g., PutBucketPolicy, DeleteBucketPolicy). By enabling CloudTrail on the S3 bucket or using a trail that logs data events for S3, you can monitor and detect unauthorized policy modifications in near real-time through the CloudTrail event history or by delivering logs to Amazon CloudWatch Logs for further analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail records management events in your account, including the PutBucketPolicy API call that modifies an S3 bucket policy. This gives you a complete, auditable history of who made the change, from which IP address, and when, making it a primary service for detecting and investigating policy changes.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes streams of data such as DNS queries, VPC Flow Logs, and CloudTrail management events to identify malicious activity like unauthorized access or crypto mining. It does not natively track or report on S3 bucket policy modifications as a compliance or change-management function, and it focuses on anomalies indicating threats, not on configuration drift or policy audit.

  • ✗

    Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs stores and aggregates log output from applications and AWS services, allowing you to search and create metric filters and alarms on textual patterns. However, detecting an S3 bucket policy change would require you to separately send CloudTrail events into CloudWatch Logs and build a custom filter; CloudWatch Logs itself does not actively monitor or detect bucket policy modifications natively.

  • ✓

    AWS Config

    Why this is correct

    AWS Config continuously records and evaluates configuration changes to AWS resources, including S3 buckets and their bucket policies. It maintains a configuration timeline and can trigger rules to flag noncompliant policies, giving you the ability to detect and alert on any alteration to an S3 bucket policy as part of its managed configuration tracking.

  • ✗

    Amazon VPC Flow Logs

    Why it's wrong here

    Amazon VPC Flow Logs capture metadata about IP traffic flowing to and from network interfaces in your VPC, such as source and destination addresses, ports, and packet counts. They provide visibility into network-level activity but do not capture API calls or management operations like PutBucketPolicy, so they cannot be used to detect S3 bucket policy changes.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.