Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Cloud Security Operations Practice Question

A cloud security team needs to ensure that all AWS API activity across a multi-account organization is captured in a tamper-evident, immutable log that can be queried later for forensic analysis. The organization uses AWS Organizations with a dedicated security account. Which approach BEST meets these requirements?

⚠ Common exam trap

The trap here is assuming that enabling CloudTrail in each account or exporting GuardDuty findings provides a centralized, immutable audit trail, when only an organization trail with S3 Object Lock and integrity validation meets tamper-evident, organization-wide forensic requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail as an organization trail that delivers logs to a centralized S3 bucket with S3 Object Lock in compliance mode and validate log file integrity.

Centralized, tamper-evident API logging in AWS Organizations is achieved with an organization trail that aggregates events into a single S3 bucket. S3 Object Lock in compliance mode prevents anyone, including the root user, from deleting or overwriting objects for the retention period, while CloudTrail log file integrity validation uses digest files to prove logs were not altered, which is essential for forensic admissibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure each member account to send AWS CloudTrail events to a local CloudWatch Logs group and rely on the default 90-day retention.

    Why it's wrong here

    Per-account CloudTrail to CloudWatch Logs does not centralize logs, and the default retention is insufficient for long-term forensics. A compromised account administrator could alter or delete the log group, breaking tamper-evidence. This approach also requires manual configuration in every account, increasing the risk of gaps and inconsistent coverage.

  • ✗

    Use AWS Config to record configuration changes across accounts and store the configuration history in the security account for later retrieval.

    Why it's wrong here

    AWS Config records resource configuration state and changes, not API activity. It cannot capture read-only API calls, authentication events, or data-plane operations, so it cannot provide a complete forensic record of who did what. It is complementary to CloudTrail but does not replace it for API activity logging.

  • ✓

    Enable AWS CloudTrail as an organization trail that delivers logs to a centralized S3 bucket with S3 Object Lock in compliance mode and validate log file integrity.

    Why this is correct

    An organization trail automatically applies to all accounts in AWS Organizations, delivering a single consolidated record of API activity. Delivering to a centralized S3 bucket protected by S3 Object Lock in compliance mode prevents deletion or alteration, and CloudTrail log file integrity validation provides cryptographic proof that logs were not tampered with, satisfying forensic-grade requirements.

  • ✗

    Enable Amazon GuardDuty in the security account and export its findings to an S3 bucket with versioning enabled for long-term storage.

    Why it's wrong here

    GuardDuty is a threat detection service that produces findings based on analyzed telemetry; it does not record raw API activity. Exporting findings provides investigative leads but not a complete, immutable audit trail of all API calls. Versioning alone also does not prevent deletion, so tamper-evidence is not guaranteed.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.