Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Match each AWS Config rule to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Checks that resources have specified tags

Ensures EBS volumes are encrypted

Prevents public read access on S3 buckets

Verifies CloudTrail is enabled

Checks for IAM policies granting full admin access

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

s3-bucket-public-read-prohibited: Checks if S3 buckets allow public read access

The correct matches are: s3-bucket-public-read-prohibited with S3 public read check, restricted-ssh with SSH access check, iam-user-no-policies-check with no attached policies, and cloud-trail-cloud-watch-logs-enabled with CloudWatch integration. Common confusions include swapping definitions between different rule types.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    s3-bucket-public-read-prohibited: Checks if S3 buckets allow public read access

    Why this is correct

    The AWS Config managed rule s3-bucket-public-read-prohibited evaluates both bucket policies and bucket ACLs to determine if an S3 bucket allows any form of public read access. When the rule reports NON_COMPLIANT, it means anonymous users can list or retrieve objects, a leading cause of AWS data breaches. The rule requires the bucket to block all public access settings or have explicit deny statements preventing public reads. This aligns with the AWS Security Hub 'S3.1' finding for public read access.

  • ✓

    restricted-ssh: Checks security groups for unrestricted SSH access from the internet

    Why this is correct

    The restricted-ssh rule examines the inbound rules of every EC2 security group in scope and flags any rule that allows TCP port 22 from the IP range 0.0.0.0/0. Open SSH access from any IPv4 address is a classic attack vector, enabling brute-force attacks and potential unauthorized server access. The rule is designed to enforce least-privilege network access, allowing you to whitelist only specific CIDR blocks or security group source references. It does not evaluate other ports, such as RDP or HTTP, which are covered by separate rules.

  • ✓

    iam-user-no-policies-check: Checks that no IAM users have managed policies attached directly

    Why this is correct

    The iam-user-no-policies-check rule inspects each IAM user and verifies that no managed policies are directly attached to the user principal, regardless of whether those policies are AWS managed or customer managed. Directly attached policies on users lead to permission sprawl and make access reviews difficult, because users can inherit permissions outside group structures. The rule pushes administrators to adopt group-based authorization, where policies live on IAM groups and users are simply members. If any user has a directly attached policy, the rule returns NON_COMPLIANT, even if the same policy is also attached to a group.

  • ✓

    cloud-trail-cloud-watch-logs-enabled: Checks CloudTrail trails have CloudWatch Logs integration

    Why this is correct

    This rule validates that each CloudTrail trail delivers its log files to a CloudWatch Logs log group, as configured through the trail's CloudWatchLogsLogGroupArn property. Sending CloudTrail events to CloudWatch Logs enables near-real-time monitoring, metric filters with pattern matching, and CloudWatch Alarms for security-critical API calls. Without this integration, trails may store logs in S3 but become 'silent' for operational alerting, making it difficult to respond to unusual account activity. The rule becomes NON_COMPLIANT if a trail exists but has no CloudWatch Logs destination.

  • ✗

    s3-bucket-public-read-prohibited: Checks security groups for unrestricted SSH access

    Why it's wrong here

    This statement incorrectly assigns the functionality of the restricted-ssh rule to the S3 bucket public-read prohibition rule. In AWS Config, the restricted-ssh rule evaluates EC2 security group inbound rules, whereas s3-bucket-public-read-prohibited assesses S3 bucket policies and ACLs for public read grants. These two rules operate on entirely different resource types and address different security domains: network access control versus object-level storage permissions. Therefore, while the description accurately describes a real AWS Config rule, it does not match the indicated rule name, making this answer option incorrect.

  • ✗

    encrypted-volumes: Checks that no IAM users have inline policies

    Why it's wrong here

    This option misattributes the encrypted-volumes rule, whose actual function is to check that all Amazon EBS volumes have encryption enabled, typically using AWS KMS keys. IAM user inline policy checks belong to a distinct set of rules such as iam-user-no-policies-check or iam-user-secrets-check — none of which involve disk-level encryption. The confusion reflects a common mix-up between two separate compliance domains: storage encryption (EBS) and identity policy management (IAM). Because the description does not reflect what encrypted-volumes actually does, this match is incorrect.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.