Automatically Enforce S3 Bucket Encryption with AWS Config
A company's security policy requires that all Amazon S3 buckets have default encryption enabled (SSE-S3 or SSE-KMS). A recent audit found several buckets without encryption enabled. The company wants an automated solution to continuously monitor all existing and new S3 buckets, detect any bucket that does not have default encryption enabled, and automatically remediate by enabling encryption. The solution must also maintain a compliance score and allow the security team to review non-compliant resources. Which AWS service should the company use to meet these requirements?
Quick Answer
The answer is AWS Config with a managed rule and automatic remediation. This service continuously evaluates all existing and new S3 buckets against the encryption requirement using the `s3-bucket-server-side-encryption-enabled` managed rule, and when a non-compliant bucket is detected, it triggers an AWS Systems Manager Automation document to automatically enable default encryption (SSE-S3 or SSE-KMS), while also providing a compliance score dashboard for the security team to review. On the AWS Certified Cloud Practitioner CLF-C02 exam, this scenario tests your understanding of how AWS Config enforces compliance through automated detective and corrective controls, often appearing as a trap where candidates mistakenly choose AWS CloudTrail (which only logs API calls) or AWS Trusted Advisor (which provides manual checks without auto-remediation). Remember the key pairing: AWS Config detects and scores, Systems Manager Automation fixes. A useful memory tip is "Config catches, Automation patches" — think of Config as the security guard who spots the violation, and Automation as the repair crew that locks the door.
⚠ Common exam trap
Test-takers frequently confuse AWS Config's compliance evaluation and remediation capabilities with GuardDuty's threat detection or Trusted Advisor's advisory checks, but only AWS Config provides continuous monitoring, automated remediation, and a compliance score for resource configuration rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config with a managed rule (s3-bucket-server-side-encryption-enabled) and an automatic remediation action using an AWS Systems Manager Automation document
AWS Config with the managed rule `s3-bucket-server-side-encryption-enabled` continuously evaluates S3 buckets against the encryption requirement. When a non-compliant bucket is detected, an automatic remediation action can invoke an AWS Systems Manager Automation document to enable default encryption (SSE-S3 or SSE-KMS). AWS Config also provides a compliance score dashboard and allows the security team to review non-compliant resources, meeting all stated requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config with a managed rule (s3-bucket-server-side-encryption-enabled) and an automatic remediation action using an AWS Systems Manager Automation document
Why this is correct
AWS Config continuously evaluates resource configurations against rules. The managed rule checks for S3 bucket default encryption. Automatic remediation via Systems Manager Automation can enable encryption on non-compliant buckets. This meets all stated requirements: continuous monitoring, detection, remediation, compliance score, and review capability.
- ✗
Amazon GuardDuty with a finding type for S3 bucket encryption
Why it's wrong here
Amazon GuardDuty is a threat detection service that identifies malicious activity and unauthorized behavior. It does not monitor configuration compliance such as S3 bucket encryption settings, nor does it provide automatic remediation or compliance scores.
When this WOULD be correct
If the question asked for a service to detect anomalous S3 access patterns or potential security threats (e.g., credential compromise), GuardDuty would be correct.
- ✗
AWS Trusted Advisor with the S3 Bucket Permissions check
Why it's wrong here
AWS Trusted Advisor checks S3 bucket permissions (public access) but not default encryption. It provides recommendations but does not automatically remediate or maintain a compliance score for encryption settings.
When this WOULD be correct
AWS Trusted Advisor would be correct if the question asked for a service to identify S3 buckets with public read/write access or overly permissive bucket policies, and the requirement was for a one-time or periodic advisory check without automated remediation or compliance scoring.
- ✗
AWS CloudTrail with a trail that logs S3 API calls and an Amazon CloudWatch alarm
Why it's wrong here
AWS CloudTrail records API activity for audit purposes. It does not monitor current resource configurations, enforce encryption policies, or provide automatic remediation. CloudWatch alarms can notify on specific events but cannot detect non-compliant bucket encryption states or fix them.
When this WOULD be correct
If the requirement were to detect unauthorized S3 API calls (e.g., PutObject without encryption) and alert in real time, CloudTrail with CloudWatch alarms would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS Config with a managed rule (s3-bucket-server-side-encryption-enabled) and an automatic remediation action using an AWS Systems Manager Automation documentCorrect answer▾
Why this is correct
AWS Config continuously evaluates resource configurations against rules. The managed rule checks for S3 bucket default encryption. Automatic remediation via Systems Manager Automation can enable encryption on non-compliant buckets. This meets all stated requirements: continuous monitoring, detection, remediation, compliance score, and review capability.
✗Amazon GuardDuty with a finding type for S3 bucket encryptionWrong answer — click to see why▾
Why this is wrong here
Amazon GuardDuty does not monitor S3 bucket encryption settings; it detects threats like suspicious API calls or unauthorized access, not compliance with encryption policies.
★ When this WOULD be the correct answer
If the question asked for a service to detect anomalous S3 access patterns or potential security threats (e.g., credential compromise), GuardDuty would be correct.
Why candidates choose this
Candidates may confuse GuardDuty's security monitoring capabilities with compliance monitoring, assuming it can check encryption settings.
✗AWS Trusted Advisor with the S3 Bucket Permissions checkWrong answer — click to see why▾
Why this is wrong here
AWS Trusted Advisor's S3 Bucket Permissions check only reviews bucket access policies and permissions, not default encryption settings. It cannot detect or remediate missing encryption, nor does it provide compliance scoring or automated remediation.
★ When this WOULD be the correct answer
AWS Trusted Advisor would be correct if the question asked for a service to identify S3 buckets with public read/write access or overly permissive bucket policies, and the requirement was for a one-time or periodic advisory check without automated remediation or compliance scoring.
Why candidates choose this
Candidates may confuse Trusted Advisor's security checks with encryption checks, or assume it covers all security best practices including encryption, leading them to select it as a monitoring tool.
✗AWS CloudTrail with a trail that logs S3 API calls and an Amazon CloudWatch alarmWrong answer — click to see why▾
Why this is wrong here
CloudTrail logs S3 API calls but cannot detect encryption status or enforce compliance; CloudWatch alarms only react to metrics, not audit encryption settings.
★ When this WOULD be the correct answer
If the requirement were to detect unauthorized S3 API calls (e.g., PutObject without encryption) and alert in real time, CloudTrail with CloudWatch alarms would be correct.
Why candidates choose this
Candidates may think logging all S3 API calls (CloudTrail) plus alerting (CloudWatch) can monitor encryption, but they lack the continuous compliance evaluation and automated remediation needed.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CLF-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company's compliance team needs to enforce a policy that all Amazon S3 buckets must have 'Block all public access' enabled. If a bucket is created without this setting, the company wants the policy to be automatically remediated within minutes without manual intervention. The solution must check for compliance continuously and apply the fix automatically. Which AWS service should the company use to meet these requirements?
medium- ✓ A.AWS Config with an AWS Config rule and an automatic remediation action
- B.Amazon GuardDuty
- C.AWS CloudTrail
- D.AWS Identity and Access Management (IAM)
Why A: AWS Config can continuously evaluate the configuration of S3 buckets against a managed rule like 's3-bucket-public-read-prohibited' or 's3-bucket-public-write-prohibited'. When a noncompliant bucket is detected, AWS Config can automatically trigger a remediation action using an AWS Systems Manager Automation document (e.g., 'AWS-DisableS3BucketPublicReadWrite') to enable 'Block all public access' within minutes, without manual intervention.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.