Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A SysOps administrator needs to ensure that all S3 buckets in the account are logged to CloudTrail for data events. The administrator enables CloudTrail with data events for S3 and selects 'All buckets' in the current account. However, after a week, they notice that some buckets are not being logged. What is the most likely reason?

⚠ Common exam trap

The trap is that candidates may assume selecting ‘All buckets’ automatically includes buckets across all regions, but trails need to be configured as multi-region or appropriate regional trails must be created to cover all regions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The S3 buckets are in a different AWS Region from the CloudTrail trail.

The most likely reason some buckets are not being logged is that those buckets reside in a different AWS Region than the one where the CloudTrail trail is configured. If the administrator creates a single-region trail and selects ‘All buckets’ for data events, the trail will only capture data events for S3 buckets in that specific region. Buckets in other regions will not be logged, resulting in partial logging coverage. Option C correctly identifies this regional mismatch.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IAM user who created the trail does not have s3:PutObject permissions on the buckets.

    Why it's wrong here

    The IAM user who creates a CloudTrail trail is not required to hold s3:PutObject permissions on the source S3 buckets. CloudTrail writes log files to the destination S3 bucket using its own AWS service principal, authorized via the trail's bucket policy or an IAM role, not the creating user's credentials. Once the trail is created, the capture of data events for a bucket relies on CloudTrail's internal permissions and the bucket's ARN being included in the trail's event selector, not on the initiator's IAM rights. Consequently, a lack of s3:PutObject on the creator's part would not cause selective missing logs.

  • ✗

    The S3 buckets do not have a bucket policy that allows CloudTrail to write the log files.

    Why it's wrong here

    A missing bucket policy on the CloudTrail destination bucket that fails to grant the CloudTrail service principal s3:PutObject would stop all log delivery, not just for some buckets. Since the scenario indicates that only some S3 buckets have absent logs, the trail is obviously delivering logs successfully for at least some buckets. Moreover, the relevant bucket policy is on the log destination bucket, not on the source buckets whose data events are being monitored; CloudTrail does not require write permissions to the source buckets themselves. Therefore, an absent bucket policy cannot selectively omit logs for specific buckets.

  • ✓

    The S3 buckets are in a different AWS Region from the CloudTrail trail.

    Why this is correct

    CloudTrail trails operate on a regional scope unless explicitly created as multi-region. When a trail is active in only one AWS Region, it records S3 data events exclusively for buckets located in that same Region; bucket-level and object-level operations in other Regions never appear in the trail's delivered log files. To capture data events for all buckets, the trail must be configured as multi-region or separate trails must be created per Region. Thus, having buckets spread across Regions while the trail is single-Region explains why only some buckets are missing logs.

  • ✗

    The S3 buckets have server access logging enabled, which conflicts with CloudTrail logging.

    Why it's wrong here

    Server access logging and CloudTrail logging are two independent mechanisms that do not interfere with each other. Server access logging captures raw HTTP-level requests to a bucket, while CloudTrail records AWS API calls, including S3 data events, and uses its own delivery pipeline to write log files. Enabling server access logging on a bucket has no effect on CloudTrail's ability to capture data events, and both can operate simultaneously. Therefore, this configuration cannot be the reason only some buckets have missing CloudTrail logs.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.