Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company uses AWS CloudTrail to log API calls across all regions. The SysOps administrator notices that logs for a specific region are missing from the centralized S3 bucket. What is the most likely cause?

⚠ Common exam trap

Many candidates assume missing logs are due to a permissions or policy issue (options B or D), when in fact the most common root cause is a simple configuration oversight where the trail is not set to log from all regions or the specific region was not included.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The CloudTrail trail is not enabled for that region.

CloudTrail trails can be configured to log API calls from specific regions or all regions. If logs for a particular region are missing from the centralized S3 bucket, the most likely cause is that the trail was not enabled for that region during trail creation or update. By default, a trail applied to all regions will automatically log activity from every region, but if the trail is configured for a single region or a subset, other regions will not have their logs delivered.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The CloudTrail trail is not enabled for that region.

    Why this is correct

    CloudTrail trails are regional resources by default. If the trail was created for a single region, it captures API calls only in that region, and you must explicitly configure a multi-region trail or create separate trails for other regions. The absence of logs for a specific region strongly indicates that no trail is enabled in that region.

  • ✗

    The S3 bucket policy denies write access from CloudTrail for that region.

    Why it's wrong here

    An S3 bucket policy is a resource policy that applies to all write requests to the bucket regardless of the source region. If CloudTrail is denied write access by the bucket policy, log delivery would fail for every trail using that bucket across all regions, not selectively for one region. A region-specific logging gap is far more likely to be a trail configuration issue than a bucket policy misconfiguration.

  • ✗

    CloudTrail log file validation is disabled.

    Why it's wrong here

    Log file validation is an optional CloudTrail feature that creates a SHA-256 hash chain and periodically publishes digest files so you can confirm the integrity of recorded log files. It operates entirely on delivered logs and does not influence whether CloudTrail captures or delivers events in any region. Disabling validation would merely remove your ability to detect tampering; it would never produce missing log entries.

  • ✗

    The IAM role for CloudTrail does not have permissions to write logs from that region.

    Why it's wrong here

    The IAM role that CloudTrail assumes to write logs to S3 or CloudWatch Logs is an account-level identity with no regional boundaries. If that role lacks the necessary permissions, delivery fails for every region the trail covers, because the same role is used across the trail's configuration. A single region without logs therefore points to a trail that is not enabled in that region, not an IAM permission problem.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.