SAA-C03 Design Secure Architectures Practice Question
A security auditor requires that all EC2 instances must be running with specific software versions and that any instance not compliant with these versions must be automatically terminated. Which THREE services should be used to achieve this? (Select THREE.)
⚠ Common exam trap
Candidates often overlook AWS Config for compliance monitoring. They may select only Systems Manager, but Systems Manager detects the state, while Config is required to trigger the remediation workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Inventory.
Combining AWS Systems Manager for inventory and automation, AWS Config for continuous compliance monitoring, and Lambda for remediation provides a fully automated governance framework. This approach ensures that the environment is continuously scanned for drift, and non-compliant resources are immediately addressed without human intervention. This setup is crucial for meeting strict regulatory requirements where automated enforcement of security and operational standards is mandatory across a large-scale AWS environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Systems Manager Inventory.
Why this is correct
Systems Manager Inventory collects metadata about software, applications, and configurations installed on EC2 instances. This provides the visibility needed to identify which instances are running the non-compliant software versions, which is the foundational step for both reporting and triggering the remediation actions required by the security audit.
- ✓
AWS Config.
Why this is correct
AWS Config monitors the configuration of AWS resources and evaluates them against custom rules. It can detect when an instance configuration or software state drifts from the defined compliant baseline. This makes it the ideal tool to continuously track compliance status and trigger notifications or remediation actions.
- ✓
AWS Lambda.
Why this is correct
Lambda acts as the remediation engine. When AWS Config detects an instance that is non-compliant, it can trigger a Lambda function to perform the termination or remediation. This automated response satisfies the requirement that non-compliant instances must be removed immediately, ensuring the infrastructure stays within the required security parameters.
- ✗
AWS Trusted Advisor.
Why it's wrong here
Trusted Advisor provides high-level recommendations based on best practices, but it is not a tool for enforcing strict configuration compliance or automated remediation of software versions. It cannot be used to trigger termination actions on instances that fail to meet specific software version checks as requested by the auditor.
- ✗
AWS CloudFront.
Why it's wrong here
CloudFront is a content delivery network used to serve static and dynamic content globally. It has no role in managing EC2 instance software versions or enforcing compliance policies. Using CloudFront to attempt to manage instance state is technically irrelevant and will not fulfill the audit requirements described in the scenario.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
About these practice questions
One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.