CCSP Cloud Security Operations Practice Question
A security team is enhancing logging in AWS to capture detailed data events for S3 buckets. Which TWO of the following should be enabled to achieve comprehensive monitoring of S3 data access? (Choose two.)
⚠ Common exam trap
A common pitfall is confusing AWS Config (which monitors configuration changes) with data access logging capabilities. Candidates often incorrectly select AWS Config for monitoring S3 data access because it records resource configurations, but it does not capture individual data access events. The correct choices for comprehensive data access monitoring are S3 server access logs and CloudTrail data events for S3.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
S3 server access logs
S3 server access logs (option A) are correct because they record detailed, bucket-level access requests to S3, including the requester, bucket name, request time, request action, response status, and error code, providing granular visibility into object-level data access. AWS CloudTrail data events for S3 (option B) are also correct because they capture object-level API activity such as GetObject, PutObject, and DeleteObject, which are not recorded by CloudTrail management events, thereby delivering comprehensive monitoring of S3 data access. AWS Config (option C) is not correct because it evaluates and records resource configuration changes and compliance, not individual S3 data access requests. VPC Flow Logs (option D) is not correct because it captures IP traffic metadata for network interfaces in a VPC, not S3 object-level API operations. Amazon GuardDuty (option E) is not correct because it is a threat detection service that analyzes logs and findings, but it does not itself enable the detailed S3 data event logging required here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
S3 server access logs
Why this is correct
S3 server access logs record every request made to a bucket, including the requester, action, timestamp and response code, giving object-level audit detail. They capture data-plane access that bucket-level logging misses, satisfying the requirement for comprehensive S3 data access monitoring.
- ✓
AWS CloudTrail data events for S3
Why this is correct
CloudTrail data events record object-level S3 operations such as GetObject and PutObject, which management events omit entirely. Enabling them satisfies the stem's requirement for detailed data-event capture on S3 buckets, providing the granular access visibility that comprehensive monitoring of object reads and writes demands.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configuration changes and evaluates compliance; it does not capture S3 object-level data events such as GetObject or PutObject. It is tempting because Config tracks S3 bucket policy and ACL changes, which suits configuration-drift auditing, but the stem requires CloudTrail data events and S3 server access logging.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture IP traffic metadata for network interfaces, not S3 object-level API operations such as GetObject or PutObject. It is tempting because flow logs are a common monitoring control, but S3 data events require CloudTrail data event logging instead.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty is a threat-detection service that analyses CloudTrail management events, VPC Flow Logs and DNS logs; it does not log individual S3 object-level data events. It is tempting because GuardDuty can raise findings on suspicious S3 activity, which suits continuous threat detection, but the stem requires raw data-event logging.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.