DOP-C02 Configuration Management and IaC Practice Question
An organization uses AWS CloudFormation to manage infrastructure. They have a stack that creates an Amazon S3 bucket with a bucket policy that restricts access to a specific IAM role. During a recent security audit, it was discovered that the bucket policy was modified manually via the AWS Management Console, and the change was not reflected in the CloudFormation template. The security team wants to detect and remediate such drift automatically. Which combination of steps should be taken to achieve this?
⚠ Common exam trap
It's easy for candidates to confuse S3 event notifications (which are for object-level events) with control plane operations like PutBucketPolicy, leading them to choose Option C, or they assume AWS Config alone can remediate drift without understanding that Config does not automatically correct CloudFormation stack resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable drift detection on the CloudFormation stack and use Amazon EventBridge to trigger an AWS Lambda function that restores the original bucket policy when drift is detected.
It directly addresses the requirement to both detect and automatically remediate drift in a CloudFormation-managed S3 bucket policy. CloudFormation drift detection identifies manual changes to the bucket policy, and Amazon EventBridge can trigger an AWS Lambda function that uses the CloudFormation UpdateStack API to restore the original policy from the template, ensuring the infrastructure remains in sync with the IaC definition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudTrail to monitor PutBucketPolicy events and send alerts to the security team via Amazon SNS.
Why it's wrong here
CloudTrail records PutBucketPolicy as an audit trail, and sending those events to SNS only alerts the security team after the fact. This approach has no automated action to restore the original bucket policy, so it leaves drift unresolved and does not integrate with CloudFormation's stack-level drift detection.
- ✗
Create an AWS Config rule to check if the bucket policy matches the desired policy, and use an AWS Lambda function to automatically correct any noncompliant buckets.
Why it's wrong here
An AWS Config rule can evaluate S3 bucket policies against a desired policy, and a Lambda function could patch the bucket, but this is not CloudFormation-native remediation: the direct fix leaves the stack's drift status unchanged and the template still differs from the live resource. Config automatic remediation is a separate feature requiring explicit setup, whereas this scenario specifically asks for CloudFormation-based drift correction.
- ✗
Configure S3 event notifications to invoke an AWS Lambda function whenever the bucket policy is modified.
Why it's wrong here
S3 event notifications only support object-level events such as s3:ObjectCreated:* and s3:ObjectRemoved:*; bucket policy changes are control-plane API calls like PutBucketPolicy that never generate these notifications. A Lambda function wired to S3 events would therefore not be invoked at all when the bucket policy is modified.
- ✓
Enable drift detection on the CloudFormation stack and use Amazon EventBridge to trigger an AWS Lambda function that restores the original bucket policy when drift is detected.
Why this is correct
Drift detection compares the live S3 bucket policy against the CloudFormation template and reports resource drift. An EventBridge rule listens for CloudFormation drift-detection status-change events and invokes Lambda, which re-applies the original bucket policy or triggers a stack update to restore the resource. This closes the loop between detecting drift and automatically remediating it.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.