SOA-C02 Monitoring, Logging, and Remediation Practice Question
A SysOps administrator is investigating a security incident where an unauthorized user accessed an S3 bucket. Which TWO AWS services can the administrator use to collect and analyze the relevant logs?
⚠ Common exam trap
It's easy for candidates to confuse VPC Flow Logs with S3 access logs, thinking network-level logs can capture S3 API calls, but VPC Flow Logs only show IP traffic metadata and not the application-level S3 operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is correct because it records API calls made to S3, including who made the request, the source IP address, and the time of the action. This allows the administrator to trace the unauthorized access to a specific IAM user or role and identify the exact API operations performed, such as GetObject or PutObject.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS WAF logs
Why it's wrong here
AWS WAF logs record metadata about HTTP(S) requests that are evaluated by web access control lists, including the matching rule and whether the request was allowed or blocked. They apply only to resources protected by AWS WAF, such as Amazon CloudFront, Application Load Balancers, or API Gateway, and they do not capture S3 API operations. Since the incident involves direct S3 access, WAF logs would lack the bucket name, object key, user identity, and action details needed for investigation.
- ✗
Amazon VPC Flow Logs
Why it's wrong here
Amazon VPC Flow Logs capture network-level metadata about traffic to and from elastic network interfaces, such as source and destination IP addresses, ports, protocol, and packet counts. They do not inspect or decrypt the contents of HTTPS sessions, so while an S3 API request might create a flow log entry showing a connection to an S3 endpoint, the entry would not reveal the bucket name, object key, IAM principal, or API operation. Thus Flow Logs can indicate that a connection occurred but cannot specifically identify S3 data access during a security incident.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the correct answer because it can be configured to capture S3 data events — object-level API calls such as GetObject, PutObject, and DeleteObject — in addition to management events like CreateBucket. Each event record includes the IAM user or role that made the request, the source IP address, the request parameters, and the response, providing a complete audit trail for incident investigation. Data events are not enabled by default on a trail, so the administrator must explicitly enable them for the target bucket to ensure such logs are captured.
- ✗
Amazon Route 53 resolver logs
Why it's wrong here
Amazon Route 53 Resolver query logs record DNS queries resolved by the Route 53 Resolver inside a VPC, showing the queried domain, the answer, and the originating IP address. At most, these logs would show that a client resolved an S3 endpoint such as s3.amazonaws.com, but they would not include the bucket name, object key, HTTP method, or IAM identity. Consequently, they are not a direct source for examining S3 API activity and do not help in this S3-focused incident.
- ✓
Amazon S3 server access logs
Why this is correct
Amazon S3 server access logging is also a correct option. When enabled on a bucket, this feature generates log objects for every request served by the bucket, capturing fields such as requester, bucket name, key, request type, HTTP status, and error code. These logs are stored in a destination S3 bucket and are tightly scoped to S3 API activity, making them a valuable source for retroactive analysis. However, they are delivered on a best-effort basis and must be analyzed separately, often alongside CloudTrail to correlate with IAM identity and policy context.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.