CCSP Cloud Security Operations Practice Question
A security operations team at a healthcare company running workloads on AWS needs to ensure that all API activity in their production account is recorded and retained for 12 months, with the ability to search for specific events during a forensic investigation. The compliance officer mandates that logs must be protected from deletion by any user, including administrators. Which AWS service and configuration should the team implement to meet these requirements?
⚠ Common exam trap
Watch out — candidates often confuse AWS Config or VPC Flow Logs with CloudTrail for API activity logging, and assuming that IAM policies or lifecycle rules alone can prevent deletion by administrators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS CloudTrail with a multi-region trail, deliver logs to an S3 bucket with versioning and MFA delete enabled, and apply a bucket policy that denies deletion.
CloudTrail is the AWS service that records API activity. To meet retention and immutability, logs should be stored in S3 with versioning and MFA delete, and a bucket policy that denies deletion for all principals. This ensures logs cannot be tampered with, even by administrators, and can be queried for forensic purposes. Other services like AWS Config or VPC Flow Logs capture different data types and lack the required protection mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS CloudTrail with a multi-region trail, deliver logs to a CloudWatch Logs log group with a 12-month retention policy, and set up a subscription filter to S3.
Why it's wrong here
CloudTrail can deliver to CloudWatch Logs, but CloudWatch Logs retention policies can be changed or logs deleted by users with sufficient permissions. There is no inherent immutability. While S3 can be a target via subscription filters, the configuration described does not enforce protection against deletion. Thus, it fails the requirement that logs be protected from deletion by any user, including administrators.
- ✗
Enable AWS Config to record configuration changes and deliver snapshots to an S3 bucket with a lifecycle policy to retain for 12 months.
Why it's wrong here
AWS Config records resource configurations and changes, not API activity. It does not capture management events like RunInstances or CreateUser. While it can help with compliance auditing, it lacks the granular API event details needed for forensic investigation of user actions. Additionally, lifecycle policies alone do not prevent deletion by administrators, so the immutability requirement is unmet.
- ✗
Enable VPC Flow Logs to capture all traffic, store them in CloudWatch Logs with a 12-month retention policy, and restrict access using IAM policies.
Why it's wrong here
VPC Flow Logs capture IP traffic metadata, not API calls. They cannot provide details on who performed actions like deleting a security group or modifying an IAM role. CloudWatch Logs retention policies can be altered by administrators, and IAM policies alone do not prevent a privileged user from deleting log groups. This solution fails to meet both the API activity and immutability requirements.
- ✓
Enable AWS CloudTrail with a multi-region trail, deliver logs to an S3 bucket with versioning and MFA delete enabled, and apply a bucket policy that denies deletion.
Why this is correct
CloudTrail records API activity across regions. Delivering to an S3 bucket with versioning and MFA delete prevents accidental or malicious deletion. A bucket policy explicitly denying s3:DeleteObject for all principals, including administrators, enforces immutability. This combination meets retention and forensic search needs, as logs are stored durably and accessible via Athena or CloudTrail Lake.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.