SOA-C02 Deployment, Provisioning, and Automation Practice Question
A SysOps administrator is creating a CloudFormation template to provision an Amazon S3 bucket with versioning enabled and server access logging. Which TWO properties must be configured in the AWS::S3::Bucket resource?
⚠ Common exam trap
Test-takers frequently confuse `LoggingConfiguration` with `AccessControl` or assume `LifecycleConfiguration` is required for logging, when in fact only `VersioningConfiguration` and `LoggingConfiguration` are mandatory for the stated requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VersioningConfiguration
The `VersioningConfiguration` property must be set to `Enabled` to enable versioning on the S3 bucket. Option C is correct because the `LoggingConfiguration` property must specify the target bucket and prefix to enable server access logging. Both are explicit properties of the `AWS::S3::Bucket` resource in CloudFormation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tags
Why it's wrong here
Tags are an optional metadata layer in AWS CloudFormation that help you categorize and manage resources for cost allocation, ownership, or environment identification. In the AWS::S3::Bucket resource, the Tags property has no bearing on enabling S3 features such as versioning or server access logging, so omitting it does not block template creation. A bucket functions fully without tags, making this option incorrect for a scenario where versioning must be enabled.
- ✓
VersioningConfiguration
Why this is correct
VersioningConfiguration is the required property in an AWS::S3::Bucket template to actually enable S3 versioning. Without this property, the bucket is created with versioning disabled (the default), even if other properties like LoggingConfiguration are present. You must set Status to 'Enabled' inside this property; note that versioning can later be suspended but never fully reset to the original default, so enabling it is a one-way configuration decision.
- ✓
LoggingConfiguration
Why this is correct
LoggingConfiguration is the mandatory property for enabling S3 server access logging against the bucket. This property must specify DestinationBucketName (and optionally LogFilePrefix) to tell S3 where to deliver access logs; simply having a bucket does not produce any access logs. Without LoggingConfiguration, no log objects are generated even if AWS CloudTrail or other monitoring is active, so this property is required for that specific feature and is not optional.
- ✗
LifecycleConfiguration
Why it's wrong here
LifecycleConfiguration is entirely optional and controls automated transitions or expirations of objects using rules, such as moving old objects to S3 Glacier or deleting them after a set number of days. It is not a prerequisite for either versioning or server access logging, and you can operate a perfectly functional bucket without defining any lifecycle rules. Although lifecycle rules can act on noncurrent versions once versioning is enabled, enabling lifecycle itself does not turn on versioning or logging.
- ✗
AccessControl
Why it's wrong here
AccessControl is an optional property that lets you assign a canned ACL (for example, Private or PublicRead) at creation time, but S3 defaults to private access if you omit it. This property is not required for enabling versioning or logging, and AWS now recommends using bucket policies or IAM roles rather than ACLs for access management. Since the question is about enabling versioning and logging, AccessControl plays no necessary role in that configuration.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.