CCSP Cloud Security Operations Practice Question
A cloud security team needs to ensure that all AWS API activity across a multi-account organization is captured in a tamper-evident, immutable log that can be queried later for forensic analysis. The organization uses AWS Organizations with a dedicated security account. Which approach BEST meets these requirements?
⚠ Common exam trap
The trap here is assuming that enabling CloudTrail in each account or exporting GuardDuty findings provides a centralized, immutable audit trail, when only an organization trail with S3 Object Lock and integrity validation meets tamper-evident, organization-wide forensic requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS CloudTrail as an organization trail that delivers logs to a centralized S3 bucket with S3 Object Lock in compliance mode and validate log file integrity.
Centralized, tamper-evident API logging in AWS Organizations is achieved with an organization trail that aggregates events into a single S3 bucket. S3 Object Lock in compliance mode prevents anyone, including the root user, from deleting or overwriting objects for the retention period, while CloudTrail log file integrity validation uses digest files to prove logs were not altered, which is essential for forensic admissibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure each member account to send AWS CloudTrail events to a local CloudWatch Logs group and rely on the default 90-day retention.
Why it's wrong here
Per-account CloudTrail to CloudWatch Logs does not centralize logs, and the default retention is insufficient for long-term forensics. A compromised account administrator could alter or delete the log group, breaking tamper-evidence. This approach also requires manual configuration in every account, increasing the risk of gaps and inconsistent coverage.
- ✗
Use AWS Config to record configuration changes across accounts and store the configuration history in the security account for later retrieval.
Why it's wrong here
AWS Config records resource configuration state and changes, not API activity. It cannot capture read-only API calls, authentication events, or data-plane operations, so it cannot provide a complete forensic record of who did what. It is complementary to CloudTrail but does not replace it for API activity logging.
- ✓
Enable AWS CloudTrail as an organization trail that delivers logs to a centralized S3 bucket with S3 Object Lock in compliance mode and validate log file integrity.
Why this is correct
An organization trail automatically applies to all accounts in AWS Organizations, delivering a single consolidated record of API activity. Delivering to a centralized S3 bucket protected by S3 Object Lock in compliance mode prevents deletion or alteration, and CloudTrail log file integrity validation provides cryptographic proof that logs were not tampered with, satisfying forensic-grade requirements.
- ✗
Enable Amazon GuardDuty in the security account and export its findings to an S3 bucket with versioning enabled for long-term storage.
Why it's wrong here
GuardDuty is a threat detection service that produces findings based on analyzed telemetry; it does not record raw API activity. Exporting findings provides investigative leads but not a complete, immutable audit trail of all API calls. Versioning alone also does not prevent deletion, so tamper-evidence is not guaranteed.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.