Courseiva
Operations and Support →easyMultiple Choice

CV0-004 Operations and Support Practice Question

A cloud administrator needs to ensure that an Amazon S3 bucket containing regulated data logs every object-level access attempt, including reads and writes, for audit purposes. Which action should the administrator take?

⚠ Common exam trap

The trap here is treating S3 server access logging or event notifications as equivalent to CloudTrail data events, when only the latter provides reliable object-level audit records.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail data events for the S3 bucket and configure the trail to deliver to a log archive account.

AWS CloudTrail data events are the designated mechanism for recording object-level S3 API activity, including reads and writes, in a structured and reliable manner. Sending the trail to a dedicated log archive account strengthens the audit posture by separating log custody from the account being monitored.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an S3 event notification to publish to Amazon SNS whenever an object is created in the bucket.

    Why it's wrong here

    S3 event notifications fire only on specific object events such as creation or deletion and do not record read access attempts. They also deliver asynchronous messages that are not designed as a tamper-evident audit log, so they cannot satisfy the requirement to capture every object-level access attempt.

  • ✗

    Enable S3 server access logging on the bucket and deliver the logs to a separate logging bucket.

    Why it's wrong here

    Server access logging records requests to the bucket but delivers logs on a best-effort basis with possible delays and no guarantee of completeness. It also does not capture object-level data events in a structured, queryable format, so it is insufficient for a strict audit requirement that demands every access attempt be recorded reliably.

  • ✗

    Enable S3 Object Lock in governance mode on the bucket to prevent deletion of audit records.

    Why it's wrong here

    Object Lock protects objects from deletion or overwrite but does not generate any record of access attempts. It addresses retention of data already in the bucket, not the requirement to log every read and write, so it fails to meet the audit logging objective described in the scenario.

  • ✓

    Enable AWS CloudTrail data events for the S3 bucket and configure the trail to deliver to a log archive account.

    Why this is correct

    CloudTrail data events capture object-level API activity such as GetObject and PutObject for the specified bucket, providing a reliable, structured audit record of every access attempt. Delivering the trail to a separate log archive account supports immutability and separation of duties, which is the expected pattern for regulated data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.