Fix CloudTrail-to-S3 delivery by verifying the bucket policy and that the bucket exists

Answer Correct answer: A, D — verify the S3 bucket policy grants CloudTrail write access and that the configured bucket still exists.

AWS CloudTrail is being used to monitor API calls in an organization. An audit revealed that CloudTrail is failing to deliver events to Amazon S3 as expected. What initial actions should be taken to allow delivery of CloudTrail events to S3? (Choose two.)

  1. Verify that the S3 bucket policy allows CloudTrail to write objects. Correct Answer
  2. Verify that the IAM role used by CloudTrail has access to write to Amazon CloudWatch Logs.
  3. Remove any lifecycle policies on the S3 bucket that are archiving objects to S3 Glacier Flexible Retrieval.
  4. Verify that the S3 bucket defined in CloudTrail exists. Correct Answer
  5. Verify that the log file prefix defined in CloudTrail exists in the S3 bucket.

Community Votes

AD
100%

100% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

CloudTrail delivery to S3 requires a real destination bucket and a bucket policy that allows the CloudTrail service principal to put objects. The log file prefix, by contrast, is created automatically by CloudTrail and need not pre-exist, so checking for it is not an initial action. IAM role permissions for CloudWatch Logs are irrelevant to S3 delivery.

CloudTrail is not delivering events to its S3 destination. The first checks are whether the S3 bucket named in the trail actually exists and whether the bucket policy grants CloudTrail permission to write objects (s3:PutObject) with the required TLS/id conditions. Both are prerequisites for delivery; without them CloudTrail cannot write logs.

Checking the log-file prefix existence (option E)—CloudTrail creates the prefix path automatically, so its absence is not the cause. Or verifying the IAM role's CloudWatch Logs access (option B), which concerns a different destination and does not affect S3 delivery.

Community Discussion (9 comments)

youonebe 👍 2 Selected: AD
While the log file prefix is important for organizing logs within the S3 bucket, the prefix does not need to exist beforehand. CloudTrail will automatically create the necessary directories (based on the prefix) in the S3 bucket when logs are delivered. The existence of the prefix itself is not a critical requirement for the delivery of CloudTrail logs.
IPLogic 👍 1 Selected: AD
To address the issue of CloudTrail failing to deliver events to Amazon S3, the initial actions you should take are: A. Verify that the S3 bucket policy allows CloudTrail to write objects. D. Verify that the S3 bucket defined in CloudTrail exists. These steps ensure that CloudTrail has the necessary permissions to write logs to the S3 bucket and that the specified bucket is correctly set up and accessible
723993f 👍 1 Selected: AD
obvious
J0_e 👍 1 Selected: AD
AD. Prefix is optional when creating a trail
daburahjail 👍 1 Selected: AE
(E) According to this, log file prefixes should be configured correctly both in the bucket policy and in CTrail configuration. I am assuming if the bucket does not exist, the Trail configuration should fail prematurely. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/turn-on-cloudtrail-in-additional-accounts.html
Xelnak 👍 1
AE read the documentation
dhewa 👍 1 Selected: AD
AD it is.
Bad_Mat 👍 1
It's AD
SkyBlueUS 👍 1
AE might be the right answer?

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A verifies the S3 bucket policy permits CloudTrail to write objects; a missing or incorrect policy is the most common cause of failed delivery. D verifies the bucket configured in the trail still exists—if it was deleted, CloudTrail has nowhere to deliver. These two checks address the core S3-delivery prerequisites.

Why the Other Options Are Wrong

B is wrong because the IAM role's CloudWatch Logs permission pertains to a different destination and does not affect S3 delivery. C is wrong because S3 lifecycle policies archiving to Glacier do not block CloudTrail from writing new logs. E is wrong because the log-file prefix is auto-created by CloudTrail and need not pre-exist; its absence does not prevent delivery.

Community Comment Notes

Community favored A,D (86 votes). Commenters noted the prefix is optional and auto-created, and that a missing bucket or bad bucket policy are the real causes. A minority argued A,E citing documentation, but E is not a delivery prerequisite.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide