Courseiva
Security and Compliance →hardMultiple Select

SOA-C02 Security and Compliance Practice Question

A company is using AWS CloudTrail to log all API calls. The security team wants to ensure that logs are tamper-proof and stored securely. Which TWO actions should be taken? (Choose two.)

⚠ Common exam trap

SOA-C02 often tests the distinction between access control (who can read/delete) and integrity verification (detecting tampering) — candidates pick MFA Delete or cross-account logging as tamper-proofing, but the exam expects SSE-KMS for confidentiality and log file validation for integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encrypt the CloudTrail log files with SSE-KMS.

Option B is correct because enabling SSE-KMS encryption on the S3 bucket that receives CloudTrail logs protects the log files at rest with AWS KMS keys, ensuring confidentiality and helping meet the requirement that logs are stored securely. Option E is correct because CloudTrail log file validation creates a digitally signed digest file for each log, allowing you to verify that logs have not been altered or deleted after delivery, which directly addresses tamper-proofing. Option A is not required for tamper-proofing or secure storage; while a separate account can improve isolation, it is not one of the two actions that specifically ensure integrity and encryption. Option C (MFA Delete) adds protection against accidental or unauthorized deletion but does not itself make log contents tamper-proof or encrypted. Option D (S3 server access logs) only records access requests to the bucket and does not provide integrity validation or encryption of CloudTrail logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Write logs to a different AWS account.

    Why it's wrong here

    Routing CloudTrail logs to a separate account isolates them from a compromised source account, but it does not stop an authorized user with access to the destination bucket from altering or deleting the objects. The destination account still has permissions, and without integrity validation or restrictive policies, logs remain vulnerable to tampering.

  • ✓

    Encrypt the CloudTrail log files with SSE-KMS.

    Why this is correct

    SSE-KMS encrypts the CloudTrail log files at rest using a customer managed AWS KMS key, so an unauthorized user who gains access to the S3 bucket cannot read the logs without also having kms:Decrypt permissions. This protects the confidentiality of the log data, though it must be paired with log file validation to prove the logs have not been altered.

  • ✗

    Enable MFA Delete on the S3 bucket.

    Why it's wrong here

    MFA Delete requires a second authentication factor before a DELETE request on an object version is allowed, which mainly prevents accidental or malicious permanent deletion of log files. It does not prevent a user with PutObject permissions from overwriting the current version of a CloudTrail log file, so it cannot guarantee the logs have not been tampered with.

  • ✗

    Enable S3 server access logs.

    Why it's wrong here

    Enabling S3 server access logging writes detailed records of requests made to the bucket, which can help audit who accessed the CloudTrail logs after the fact, but it does not protect those logs from being changed or deleted. It is a detective control, not a preventive or integrity-preserving control, so it does not secure the CloudTrail log files themselves.

  • ✓

    Enable CloudTrail log file validation.

    Why this is correct

    CloudTrail log file validation uses SHA-256 hashing and digital signatures to create digest files, allowing you to verify that the log files were not modified or deleted after delivery. AWS publishes the public key used for validation, so you can detect any tampering with the original logs. This directly provides log integrity.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.