Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A SysOps administrator is investigating a security incident where an unauthorized user accessed an S3 bucket. Which TWO AWS services can the administrator use to collect and analyze the relevant logs?

⚠ Common exam trap

It's easy for candidates to confuse VPC Flow Logs with S3 access logs, thinking network-level logs can capture S3 API calls, but VPC Flow Logs only show IP traffic metadata and not the application-level S3 operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is correct because it records API calls made to S3, including who made the request, the source IP address, and the time of the action. This allows the administrator to trace the unauthorized access to a specific IAM user or role and identify the exact API operations performed, such as GetObject or PutObject.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS WAF logs

    Why it's wrong here

    AWS WAF logs record metadata about HTTP(S) requests that are evaluated by web access control lists, including the matching rule and whether the request was allowed or blocked. They apply only to resources protected by AWS WAF, such as Amazon CloudFront, Application Load Balancers, or API Gateway, and they do not capture S3 API operations. Since the incident involves direct S3 access, WAF logs would lack the bucket name, object key, user identity, and action details needed for investigation.

  • ✗

    Amazon VPC Flow Logs

    Why it's wrong here

    Amazon VPC Flow Logs capture network-level metadata about traffic to and from elastic network interfaces, such as source and destination IP addresses, ports, protocol, and packet counts. They do not inspect or decrypt the contents of HTTPS sessions, so while an S3 API request might create a flow log entry showing a connection to an S3 endpoint, the entry would not reveal the bucket name, object key, IAM principal, or API operation. Thus Flow Logs can indicate that a connection occurred but cannot specifically identify S3 data access during a security incident.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail is the correct answer because it can be configured to capture S3 data events — object-level API calls such as GetObject, PutObject, and DeleteObject — in addition to management events like CreateBucket. Each event record includes the IAM user or role that made the request, the source IP address, the request parameters, and the response, providing a complete audit trail for incident investigation. Data events are not enabled by default on a trail, so the administrator must explicitly enable them for the target bucket to ensure such logs are captured.

  • ✗

    Amazon Route 53 resolver logs

    Why it's wrong here

    Amazon Route 53 Resolver query logs record DNS queries resolved by the Route 53 Resolver inside a VPC, showing the queried domain, the answer, and the originating IP address. At most, these logs would show that a client resolved an S3 endpoint such as s3.amazonaws.com, but they would not include the bucket name, object key, HTTP method, or IAM identity. Consequently, they are not a direct source for examining S3 API activity and do not help in this S3-focused incident.

  • ✓

    Amazon S3 server access logs

    Why this is correct

    Amazon S3 server access logging is also a correct option. When enabled on a bucket, this feature generates log objects for every request served by the bucket, capturing fields such as requester, bucket name, key, request type, HTTP status, and error code. These logs are stored in a destination S3 bucket and are tightly scoped to S3 API activity, making them a valuable source for retroactive analysis. However, they are delivered on a best-effort basis and must be analyzed separately, often alongside CloudTrail to correlate with IAM identity and policy context.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.