SCS-C02 exam dumps

SCS-C02 practice question 143 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 143

Select 2

Your organization uses Amazon S3 to store application logs and has S3 server access logging enabled for auditing purposes. However, the security team reports that they are not receiving any logs for a specific S3 bucket. You verify that S3 server access logging is enabled on the bucket in question. What could be the potential issues causing this problem?

  1. A

    The target bucket for the logs does not have the required bucket policy to allow write access for the logging service.

  2. B

    The logging target bucket is in the same AWS Region as the source bucket.

  3. C

    The IAM role associated with the S3 bucket does not have the 's3:PutObject' permission for the logging target bucket.

  4. D

    The logging destination bucket is configured with a bucket lifecycle policy that deletes logs immediately upon delivery.

  5. E

    The S3 bucket logging configuration is using the same bucket for both the source and the destination, violating best practices.

Show answer and explanation

Correct answers: A, D

Explanation

S3 server access logging requires certain configurations to function correctly. The target bucket must have a bucket policy granting write access to the logging service. Additionally, if a lifecycle policy on the destination bucket deletes logs immediately, the logs will not be retrievable for auditing. Cross-region logging and using the same bucket for both source and destination are supported but may not align with best practices or specific organizational requirements.

  • A. Correct.

    Correct: For S3 server access logging to work, the target bucket must have a bucket policy that explicitly grants write access to the S3 logging service.

  • B. Incorrect.

    Incorrect: The logging target bucket does not have to be in the same AWS Region as the source bucket. Cross-region logging is supported.

  • C. Incorrect.

    Incorrect: S3 server access logging does not use IAM roles. It relies on the bucket policy of the target bucket to allow write access for the logging service.

  • D. Correct.

    Correct: If the destination bucket has a lifecycle policy that deletes logs immediately upon delivery, logs will not be available for review.

  • E. Incorrect.

    Incorrect: While using the same bucket for both source and destination is not a recommended practice, it does not prevent logging from working.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam