Courseiva
Cloud Security Operations →mediumMultiple Select

CCSP Cloud Security Operations Practice Question

A security team is enhancing logging in AWS to capture detailed data events for S3 buckets. Which TWO of the following should be enabled to achieve comprehensive monitoring of S3 data access? (Choose two.)

⚠ Common exam trap

A common pitfall is confusing AWS Config (which monitors configuration changes) with data access logging capabilities. Candidates often incorrectly select AWS Config for monitoring S3 data access because it records resource configurations, but it does not capture individual data access events. The correct choices for comprehensive data access monitoring are S3 server access logs and CloudTrail data events for S3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

S3 server access logs

S3 server access logs (option A) are correct because they record detailed, bucket-level access requests to S3, including the requester, bucket name, request time, request action, response status, and error code, providing granular visibility into object-level data access. AWS CloudTrail data events for S3 (option B) are also correct because they capture object-level API activity such as GetObject, PutObject, and DeleteObject, which are not recorded by CloudTrail management events, thereby delivering comprehensive monitoring of S3 data access. AWS Config (option C) is not correct because it evaluates and records resource configuration changes and compliance, not individual S3 data access requests. VPC Flow Logs (option D) is not correct because it captures IP traffic metadata for network interfaces in a VPC, not S3 object-level API operations. Amazon GuardDuty (option E) is not correct because it is a threat detection service that analyzes logs and findings, but it does not itself enable the detailed S3 data event logging required here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    S3 server access logs

    Why this is correct

    S3 server access logs record every request made to a bucket, including the requester, action, timestamp and response code, giving object-level audit detail. They capture data-plane access that bucket-level logging misses, satisfying the requirement for comprehensive S3 data access monitoring.

  • ✓

    AWS CloudTrail data events for S3

    Why this is correct

    CloudTrail data events record object-level S3 operations such as GetObject and PutObject, which management events omit entirely. Enabling them satisfies the stem's requirement for detailed data-event capture on S3 buckets, providing the granular access visibility that comprehensive monitoring of object reads and writes demands.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and evaluates compliance; it does not capture S3 object-level data events such as GetObject or PutObject. It is tempting because Config tracks S3 bucket policy and ACL changes, which suits configuration-drift auditing, but the stem requires CloudTrail data events and S3 server access logging.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata for network interfaces, not S3 object-level API operations such as GetObject or PutObject. It is tempting because flow logs are a common monitoring control, but S3 data events require CloudTrail data event logging instead.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty is a threat-detection service that analyses CloudTrail management events, VPC Flow Logs and DNS logs; it does not log individual S3 object-level data events. It is tempting because GuardDuty can raise findings on suspicious S3 activity, which suits continuous threat detection, but the stem requires raw data-event logging.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.