Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

Automatically Enforce S3 Bucket Encryption with AWS Config

A company's security policy requires that all Amazon S3 buckets have default encryption enabled (SSE-S3 or SSE-KMS). A recent audit found several buckets without encryption enabled. The company wants an automated solution to continuously monitor all existing and new S3 buckets, detect any bucket that does not have default encryption enabled, and automatically remediate by enabling encryption. The solution must also maintain a compliance score and allow the security team to review non-compliant resources. Which AWS service should the company use to meet these requirements?

Quick Answer

The answer is AWS Config with a managed rule and automatic remediation. This service continuously evaluates all existing and new S3 buckets against the encryption requirement using the `s3-bucket-server-side-encryption-enabled` managed rule, and when a non-compliant bucket is detected, it triggers an AWS Systems Manager Automation document to automatically enable default encryption (SSE-S3 or SSE-KMS), while also providing a compliance score dashboard for the security team to review. On the AWS Certified Cloud Practitioner CLF-C02 exam, this scenario tests your understanding of how AWS Config enforces compliance through automated detective and corrective controls, often appearing as a trap where candidates mistakenly choose AWS CloudTrail (which only logs API calls) or AWS Trusted Advisor (which provides manual checks without auto-remediation). Remember the key pairing: AWS Config detects and scores, Systems Manager Automation fixes. A useful memory tip is "Config catches, Automation patches" — think of Config as the security guard who spots the violation, and Automation as the repair crew that locks the door.

⚠ Common exam trap

Test-takers frequently confuse AWS Config's compliance evaluation and remediation capabilities with GuardDuty's threat detection or Trusted Advisor's advisory checks, but only AWS Config provides continuous monitoring, automated remediation, and a compliance score for resource configuration rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Config with a managed rule (s3-bucket-server-side-encryption-enabled) and an automatic remediation action using an AWS Systems Manager Automation document

AWS Config with the managed rule `s3-bucket-server-side-encryption-enabled` continuously evaluates S3 buckets against the encryption requirement. When a non-compliant bucket is detected, an automatic remediation action can invoke an AWS Systems Manager Automation document to enable default encryption (SSE-S3 or SSE-KMS). AWS Config also provides a compliance score dashboard and allows the security team to review non-compliant resources, meeting all stated requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Config with a managed rule (s3-bucket-server-side-encryption-enabled) and an automatic remediation action using an AWS Systems Manager Automation document

    Why this is correct

    AWS Config continuously evaluates resource configurations against rules. The managed rule checks for S3 bucket default encryption. Automatic remediation via Systems Manager Automation can enable encryption on non-compliant buckets. This meets all stated requirements: continuous monitoring, detection, remediation, compliance score, and review capability.

  • Amazon GuardDuty with a finding type for S3 bucket encryption

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that identifies malicious activity and unauthorized behavior. It does not monitor configuration compliance such as S3 bucket encryption settings, nor does it provide automatic remediation or compliance scores.

    When this WOULD be correct

    If the question asked for a service to detect anomalous S3 access patterns or potential security threats (e.g., credential compromise), GuardDuty would be correct.

  • AWS Trusted Advisor with the S3 Bucket Permissions check

    Why it's wrong here

    AWS Trusted Advisor checks S3 bucket permissions (public access) but not default encryption. It provides recommendations but does not automatically remediate or maintain a compliance score for encryption settings.

    When this WOULD be correct

    AWS Trusted Advisor would be correct if the question asked for a service to identify S3 buckets with public read/write access or overly permissive bucket policies, and the requirement was for a one-time or periodic advisory check without automated remediation or compliance scoring.

  • AWS CloudTrail with a trail that logs S3 API calls and an Amazon CloudWatch alarm

    Why it's wrong here

    AWS CloudTrail records API activity for audit purposes. It does not monitor current resource configurations, enforce encryption policies, or provide automatic remediation. CloudWatch alarms can notify on specific events but cannot detect non-compliant bucket encryption states or fix them.

    When this WOULD be correct

    If the requirement were to detect unauthorized S3 API calls (e.g., PutObject without encryption) and alert in real time, CloudTrail with CloudWatch alarms would be correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS Config with a managed rule (s3-bucket-server-side-encryption-enabled) and an automatic remediation action using an AWS Systems Manager Automation documentCorrect answer

Why this is correct

AWS Config continuously evaluates resource configurations against rules. The managed rule checks for S3 bucket default encryption. Automatic remediation via Systems Manager Automation can enable encryption on non-compliant buckets. This meets all stated requirements: continuous monitoring, detection, remediation, compliance score, and review capability.

Amazon GuardDuty with a finding type for S3 bucket encryptionWrong answer — click to see why

Why this is wrong here

Amazon GuardDuty does not monitor S3 bucket encryption settings; it detects threats like suspicious API calls or unauthorized access, not compliance with encryption policies.

★ When this WOULD be the correct answer

If the question asked for a service to detect anomalous S3 access patterns or potential security threats (e.g., credential compromise), GuardDuty would be correct.

Why candidates choose this

Candidates may confuse GuardDuty's security monitoring capabilities with compliance monitoring, assuming it can check encryption settings.

AWS Trusted Advisor with the S3 Bucket Permissions checkWrong answer — click to see why

Why this is wrong here

AWS Trusted Advisor's S3 Bucket Permissions check only reviews bucket access policies and permissions, not default encryption settings. It cannot detect or remediate missing encryption, nor does it provide compliance scoring or automated remediation.

★ When this WOULD be the correct answer

AWS Trusted Advisor would be correct if the question asked for a service to identify S3 buckets with public read/write access or overly permissive bucket policies, and the requirement was for a one-time or periodic advisory check without automated remediation or compliance scoring.

Why candidates choose this

Candidates may confuse Trusted Advisor's security checks with encryption checks, or assume it covers all security best practices including encryption, leading them to select it as a monitoring tool.

AWS CloudTrail with a trail that logs S3 API calls and an Amazon CloudWatch alarmWrong answer — click to see why

Why this is wrong here

CloudTrail logs S3 API calls but cannot detect encryption status or enforce compliance; CloudWatch alarms only react to metrics, not audit encryption settings.

★ When this WOULD be the correct answer

If the requirement were to detect unauthorized S3 API calls (e.g., PutObject without encryption) and alert in real time, CloudTrail with CloudWatch alarms would be correct.

Why candidates choose this

Candidates may think logging all S3 API calls (CloudTrail) plus alerting (CloudWatch) can monitor encryption, but they lack the continuous compliance evaluation and automated remediation needed.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CLF-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company's compliance team needs to enforce a policy that all Amazon S3 buckets must have 'Block all public access' enabled. If a bucket is created without this setting, the company wants the policy to be automatically remediated within minutes without manual intervention. The solution must check for compliance continuously and apply the fix automatically. Which AWS service should the company use to meet these requirements?

medium
  • A.AWS Config with an AWS Config rule and an automatic remediation action
  • B.Amazon GuardDuty
  • C.AWS CloudTrail
  • D.AWS Identity and Access Management (IAM)

Why A: AWS Config can continuously evaluate the configuration of S3 buckets against a managed rule like 's3-bucket-public-read-prohibited' or 's3-bucket-public-write-prohibited'. When a noncompliant bucket is detected, AWS Config can automatically trigger a remediation action using an AWS Systems Manager Automation document (e.g., 'AWS-DisableS3BucketPublicReadWrite') to enable 'Block all public access' within minutes, without manual intervention.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.