SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company is using AWS CloudTrail to log API activity. They need to ensure that log files are protected from unauthorized modification and can be used to verify the integrity of log files. Which AWS feature should be enabled?
⚠ Common exam trap
Many candidates confuse data protection features like encryption or deletion prevention with integrity verification, not realizing that integrity validation specifically requires a cryptographic hash chain to detect modification, not just access control or encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable CloudTrail log file integrity validation.
CloudTrail log file integrity validation uses a SHA-256 hash chain to create a digest file that can be used to verify that log files have not been modified, deleted, or tampered with after delivery. This feature is specifically designed to provide cryptographic assurance of log file integrity, meeting the requirement to protect against unauthorized modification and enable verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable CloudTrail log file integrity validation.
Why this is correct
CloudTrail log file integrity validation provides cryptographic assurance that your log files have not been tampered with. It uses SHA-256 hashing to generate a hash for each log file, and then digitally signs it with a private key. You can validate these signatures using the public key published by AWS, which lets you detect any modification, deletion, or unauthorized change to the logs, even if someone attempts to alter the digest files themselves.
- ✗
Enable S3 server-side encryption on the CloudTrail S3 bucket.
Why it's wrong here
Enabling server-side encryption (SSE) on the CloudTrail S3 bucket only encrypts the data at rest, protecting it from unauthorized access to the underlying storage. Encryption does not provide any integrity verification or tamper-evidence, because a user with valid decrypting permissions could still read, alter, and re-encrypt log files without detection. Thus, while SSE is a good security practice, it does not satisfy the requirement to prove that logs have not been modified.
- ✗
Stream CloudTrail logs to Amazon CloudWatch Logs.
Why it's wrong here
Streaming CloudTrail events to Amazon CloudWatch Logs enables real-time monitoring, metric filters, and alarms on API activity, but it does not generate any hash or digital signature for the original log files. Without cryptographic integrity checks, an attacker who modifies the CloudTrail logs—or the stream itself—can go undetected because no baseline or signature exists to compare against. This approach is reactive and provides visibility, not forensic proof of log authenticity.
- ✗
Enable S3 Multi-Factor Authentication (MFA) Delete on the CloudTrail S3 bucket.
Why it's wrong here
Enabling S3 Multi-Factor Authentication (MFA) Delete on the CloudTrail bucket requires additional authentication to delete object versions, which helps prevent accidental or unauthorized deletion. However, it does not protect against modifications to existing log objects, nor does it provide any way to verify that files have not been altered after being written. MFA Delete is a deletion control, not an integrity control, so it fails to meet the requirement of proving log file integrity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.