Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company is using Amazon CloudWatch Logs to centralize logs from multiple EC2 instances. The SysOps administrator needs to ensure that log data is encrypted at rest and in transit. Which TWO actions should the administrator take? (Choose TWO.)

⚠ Common exam trap

Test-takers frequently confuse CloudWatch Logs encryption with S3 server-side encryption options (SSE-S3 or SSE-KMS) or assume that ACM certificates are needed for agent-to-service encryption, when in fact the CloudWatch Logs agent uses AWS SDK-managed TLS automatically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encrypt the CloudWatch Logs log group using an AWS KMS customer managed key.

CloudWatch Logs supports encryption at rest using AWS KMS customer managed keys (CMKs). By associating a KMS key with a log group, all log data stored in that log group is encrypted at rest, meeting the encryption-at-rest requirement. Option D is correct because the CloudWatch Logs agent can be configured to use TLS/SSL (port 443) for log delivery, ensuring encryption in transit between the EC2 instances and CloudWatch Logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Encrypt the CloudWatch Logs log group using an AWS KMS customer managed key.

    Why this is correct

    CloudWatch Logs supports encryption at rest by associating an AWS KMS customer managed key with the log group. When this key is attached, every incoming log event is encrypted before storage and decrypted only by authorized readers; you must grant the CloudWatch Logs service permission to use the key via key policies. Using a customer managed key allows you to control rotation, access, and lifecycle independently of the default AWS-managed aws/logs key.

  • ✗

    Enable server-side encryption with S3-managed keys (SSE-S3) on the CloudWatch Logs log group.

    Why it's wrong here

    SSE-S3 is a feature for encrypting objects stored in Amazon S3, but a CloudWatch Logs log group is not an S3 bucket and has no SSE-S3 setting in its API or console. CloudWatch Logs uses its own internal storage subsystem, and encryption at rest is configured by selecting a KMS key at log group creation or via PutLogGroup policies. Referencing SSE-S3 for a log group is invalid because it mistakenly applies an S3 storage mechanism to a managed log service.

  • ✗

    Apply an S3 bucket policy that requires encryption for objects uploaded to the bucket.

    Why it's wrong here

    An S3 bucket policy that requires encryption on uploads governs only objects written directly to that bucket, and CloudWatch Logs does not store log events in S3 as part of its standard ingestion path. Logs reside in CloudWatch Logs' managed storage; an S3 bucket becomes involved only if you later export log groups via a CreateExportTask, at which point the bucket policy could enforce SSE-S3 or SSE-KMS on exported files. Therefore this option neither encrypts logs at rest in CloudWatch Logs nor affects the original log stream.

  • ✓

    Configure the CloudWatch Logs agent to use TLS/SSL for log delivery.

    Why this is correct

    Configuring the CloudWatch Logs agent to use TLS/SSL ensures that log events are encrypted in transit between your EC2 instances and the CloudWatch Logs API endpoint. The agent establishes an HTTPS connection to the regional service, preventing interception of plaintext log data on the network. This addresses the transport layer requirement but is distinct from encryption at rest; both are needed when the compliance requirement includes encrypted storage.

  • ✗

    Install an AWS Certificate Manager (ACM) certificate on the EC2 instances.

    Why it's wrong here

    ACM certificates are designed for terminating TLS on services such as Application Load Balancers, CloudFront, or API Gateway, and they are not used by the CloudWatch Logs agent when sending logs. The agent relies on the built-in TLS handshake with the AWS-managed endpoint certificate for CloudWatch Logs, so installing an ACM certificate on the EC2 instance adds no encryption or authentication for log delivery. ACM issuance and renewal also do not integrate with the CloudWatch Logs agent's runtime.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.