How to Automatically Enforce S3 Encryption and Block Public Access Across Accounts Using AWS Config
A company uses multiple AWS accounts. The security team wants to enforce two requirements for all Amazon S3 buckets: first, server-side encryption must be enabled using AWS KMS; second, no bucket can be publicly accessible. The team needs a service that continuously monitors the configuration of S3 buckets across all accounts, detects when a bucket violates either requirement, and automatically applies corrective actions (such as enabling default encryption or removing public access). Which AWS service should the security team use to meet these requirements?
Quick Answer
The answer is AWS Config. This service is the correct choice because it continuously monitors and evaluates the configuration of AWS resources—like S3 buckets—against predefined rules, such as requiring server-side encryption with AWS KMS and blocking public access. When a violation is detected, AWS Config can automatically trigger remediation actions, such as enabling default encryption or removing public bucket policies, using Systems Manager Automation or Lambda functions. On the AWS Certified Cloud Practitioner CLF-C02 exam, this scenario tests your understanding of how to enforce security policies at scale across multiple accounts, often appearing as a question that contrasts AWS Config with services like AWS CloudTrail or IAM. A common trap is choosing S3-specific features like bucket policies, but those lack continuous monitoring and automated remediation. Remember: Config is the cop that enforces the rules, not just the rulebook. Memory tip: “Config corrects configurations” across accounts.
⚠ Common exam trap
Many exam-takers confuse AWS Config's continuous compliance monitoring and automated remediation with AWS Trusted Advisor's advisory checks or AWS IAM Access Analyzer's policy analysis, failing to recognize that only AWS Config provides both detection and automatic corrective actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it provides continuous monitoring, evaluation, and automated remediation of resource configurations across multiple accounts. With AWS Config rules (e.g., managed rules like `s3-bucket-server-side-encryption-enabled` and `s3-bucket-public-read-prohibited`), you can detect noncompliant S3 buckets and trigger AWS Systems Manager Automation documents or Lambda functions to automatically enable default encryption or remove public access. AWS Config also supports multi-account aggregation via an aggregator, allowing the security team to enforce these requirements across all accounts from a single management account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config
Why this is correct
AWS Config is the correct choice because it continuously evaluates resource configurations against desired policies (e.g., S3 bucket encryption and public access) and can automatically remediate non-compliant resources using pre-defined actions, meeting all requirements.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor inspects AWS environments and provides best practice recommendations (including S3 bucket permissions and encryption) but does not support automatic remediation of non-compliant resources.
When this WOULD be correct
A question asking for a service that provides a one-time or periodic review of AWS best practices, such as checking for idle RDS instances or underutilized EC2 instances, and offers recommendations without requiring automated remediation.
- ✗
AWS IAM Access Analyzer
Why it's wrong here
AWS IAM Access Analyzer helps identify resources shared with external entities (e.g., S3 buckets with public or cross-account access) but does not monitor or enforce encryption settings, nor does it automatically apply corrective actions.
When this WOULD be correct
A security team needs to identify S3 buckets that are shared with external AWS accounts or allow public access, and they want a service that generates findings for review without automatically remediating. IAM Access Analyzer would be the correct choice for this specific use case.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API activity for governance and audit but does not monitor resource configurations or automatically enforce compliance rules; it cannot detect or remediate non-compliant S3 bucket settings.
When this WOULD be correct
A security team needs to audit all API calls made to S3 buckets across multiple accounts to investigate a data breach. They require a service that logs who made changes, when, and from which IP address, with the logs stored in a central S3 bucket for analysis.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS ConfigCorrect answer▾
Why this is correct
AWS Config is the correct choice because it continuously evaluates resource configurations against desired policies (e.g., S3 bucket encryption and public access) and can automatically remediate non-compliant resources using pre-defined actions, meeting all requirements.
✗AWS Trusted AdvisorWrong answer — click to see why▾
Why this is wrong here
AWS Trusted Advisor provides best-practice checks and recommendations but does not automatically apply corrective actions or continuously monitor for compliance with custom rules like enabling KMS encryption.
★ When this WOULD be the correct answer
A question asking for a service that provides a one-time or periodic review of AWS best practices, such as checking for idle RDS instances or underutilized EC2 instances, and offers recommendations without requiring automated remediation.
Why candidates choose this
Candidates may confuse Trusted Advisor's security checks (e.g., S3 bucket permissions) with the ability to enforce and remediate policies, overlooking that it only advises and does not take automated actions.
✗AWS IAM Access AnalyzerWrong answer — click to see why▾
Why this is wrong here
AWS IAM Access Analyzer analyzes resource-based policies to identify resources shared with external entities, but it does not continuously monitor S3 bucket configurations for encryption or automatically apply corrective actions.
★ When this WOULD be the correct answer
A security team needs to identify S3 buckets that are shared with external AWS accounts or allow public access, and they want a service that generates findings for review without automatically remediating. IAM Access Analyzer would be the correct choice for this specific use case.
Why candidates choose this
Candidates may confuse IAM Access Analyzer's ability to detect public access with the broader compliance monitoring and auto-remediation capabilities of AWS Config, or they may think 'Access Analyzer' implies continuous monitoring of all access-related settings.
✗AWS CloudTrailWrong answer — click to see why▾
Why this is wrong here
AWS CloudTrail records API activity for auditing but does not continuously monitor resource configurations or automatically apply corrective actions. It cannot detect S3 bucket encryption or public access violations and lacks remediation capabilities.
★ When this WOULD be the correct answer
A security team needs to audit all API calls made to S3 buckets across multiple accounts to investigate a data breach. They require a service that logs who made changes, when, and from which IP address, with the logs stored in a central S3 bucket for analysis.
Why candidates choose this
Candidates may confuse CloudTrail's logging and monitoring capabilities with configuration compliance, thinking that recording API calls can help detect misconfigurations, but CloudTrail does not evaluate configurations or enforce rules.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CLF-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS Organizations and manages hundreds of AWS accounts. The security policy requires that all Amazon S3 buckets be encrypted using a specific AWS KMS customer-managed key (CMK). The security team wants to automatically detect any S3 bucket that is not encrypted with the required CMK and automatically apply the correct encryption configuration without manual intervention. Which AWS service should the security team use to implement this automated compliance enforcement?
medium- A.Amazon GuardDuty
- ✓ B.AWS Config
- C.AWS CloudTrail
- D.AWS Trusted Advisor
Why B: AWS Config is the correct service because it provides managed rules (e.g., s3-bucket-server-side-encryption-enabled and s3-bucket-kms-encryption-specific-key) that can evaluate whether S3 buckets are encrypted with the required KMS customer-managed key. When a noncompliant bucket is detected, AWS Config can trigger an AWS Lambda function via an Amazon EventBridge rule to automatically apply the correct encryption configuration, enabling automated remediation without manual intervention.
Variation 2. A company uses AWS Organizations to manage multiple accounts. The security team wants to continuously monitor the configurations of all AWS resources across the organization and receive alerts when a resource violates a compliance rule. For example, they want to ensure that all Amazon RDS databases are not publicly accessible, and that any new RDS instance created with public access enabled is automatically flagged. The team does not want to build custom scripts for monitoring. Which AWS service should the security team use to meet these requirements?
medium- A.AWS CloudTrail
- ✓ B.AWS Config
- C.AWS Trusted Advisor
- D.Amazon GuardDuty
Why B: AWS Config is the correct service because it provides continuous monitoring and recording of AWS resource configurations, and it can evaluate those configurations against custom or managed rules (e.g., 'rds-instance-public-access-check'). When a resource like an RDS instance violates a rule (e.g., being publicly accessible), AWS Config can automatically flag it and trigger an alert via Amazon SNS, all without requiring custom scripts.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.