SOA-C02 Security and Compliance Practice Question
A company is using AWS CloudTrail to log all API calls. The security team wants to ensure that logs are tamper-proof and stored securely. Which TWO actions should be taken? (Choose two.)
⚠ Common exam trap
SOA-C02 often tests the distinction between access control (who can read/delete) and integrity verification (detecting tampering) — candidates pick MFA Delete or cross-account logging as tamper-proofing, but the exam expects SSE-KMS for confidentiality and log file validation for integrity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Encrypt the CloudTrail log files with SSE-KMS.
Option B is correct because enabling SSE-KMS encryption on the S3 bucket that receives CloudTrail logs protects the log files at rest with AWS KMS keys, ensuring confidentiality and helping meet the requirement that logs are stored securely. Option E is correct because CloudTrail log file validation creates a digitally signed digest file for each log, allowing you to verify that logs have not been altered or deleted after delivery, which directly addresses tamper-proofing. Option A is not required for tamper-proofing or secure storage; while a separate account can improve isolation, it is not one of the two actions that specifically ensure integrity and encryption. Option C (MFA Delete) adds protection against accidental or unauthorized deletion but does not itself make log contents tamper-proof or encrypted. Option D (S3 server access logs) only records access requests to the bucket and does not provide integrity validation or encryption of CloudTrail logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Write logs to a different AWS account.
Why it's wrong here
Routing CloudTrail logs to a separate account isolates them from a compromised source account, but it does not stop an authorized user with access to the destination bucket from altering or deleting the objects. The destination account still has permissions, and without integrity validation or restrictive policies, logs remain vulnerable to tampering.
- ✓
Encrypt the CloudTrail log files with SSE-KMS.
Why this is correct
SSE-KMS encrypts the CloudTrail log files at rest using a customer managed AWS KMS key, so an unauthorized user who gains access to the S3 bucket cannot read the logs without also having kms:Decrypt permissions. This protects the confidentiality of the log data, though it must be paired with log file validation to prove the logs have not been altered.
- ✗
Enable MFA Delete on the S3 bucket.
Why it's wrong here
MFA Delete requires a second authentication factor before a DELETE request on an object version is allowed, which mainly prevents accidental or malicious permanent deletion of log files. It does not prevent a user with PutObject permissions from overwriting the current version of a CloudTrail log file, so it cannot guarantee the logs have not been tampered with.
- ✗
Enable S3 server access logs.
Why it's wrong here
Enabling S3 server access logging writes detailed records of requests made to the bucket, which can help audit who accessed the CloudTrail logs after the fact, but it does not protect those logs from being changed or deleted. It is a detective control, not a preventive or integrity-preserving control, so it does not secure the CloudTrail log files themselves.
- ✓
Enable CloudTrail log file validation.
Why this is correct
CloudTrail log file validation uses SHA-256 hashing and digital signatures to create digest files, allowing you to verify that the log files were not modified or deleted after delivery. AWS publishes the public key used for validation, so you can detect any tampering with the original logs. This directly provides log integrity.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.