Courseiva

SCS-C02 AWS Config Practice Question

A company has an AWS account with a single VPC and multiple subnets. The security team wants to ensure that no network ACL (NACL) allows inbound SSH (port 22) from 0.0.0.0/0. Which AWS service can be used to detect and alert on such non-compliant NACLs?

⚠ Common exam trap

SCS-C02 often tests the distinction between detection services (GuardDuty for threats, Inspector for vulnerabilities) and compliance evaluation services (Config for configuration rules), tempting candidates to pick GuardDuty for configuration issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config continuously records resource configurations and evaluates them against rules, making it the correct service to detect non-compliant NACLs. You can use the managed rule 'nacl-no-unrestricted-ssh-rdp' (or a custom rule) to flag any NACL that allows inbound SSH from 0.0.0.0/0 and trigger alerts via Amazon EventBridge or SNS. This directly addresses the requirement to detect and alert on non-compliant NACLs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is an automated vulnerability management service that uses an agent installed on EC2 instances to assess software-level weaknesses (CVEs) and unintentional network exposure. Its Network Reachability checks analyze instance network paths, but they do not inspect the NACL configuration itself as a resource. Thus Inspector cannot flag a NACL entry permitting inbound SSH from 0.0.0.0/0 as a static compliance violation; it operates on runtime instance findings, not declarative configuration policy.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that ingests VPC Flow Logs, DNS query logs, and CloudTrail event history to identify malicious activity like anomalous SSH brute-force attempts or crypto mining. It relies on observed behavior and threat intelligence to generate findings, rather than on an expected configuration policy. Since a NACL rule permitting SSH from 0.0.0.0/0 is a static network configuration, GuardDuty will not flag it unless it correlates with actual suspicious traffic, making it unsuitable for proactive compliance evaluation.

  • ✓

    AWS Config

    Why this is correct

    AWS Config continuously records the configuration of supported resources, including Network ACLs and their inbound/outbound rules, as configuration items in a timeline. It then evaluates those config items against managed rules—such as the managed rule 'incoming-ssh-disabled'—or custom Lambda rules that can inspect each NACL entry and mark any ingress rule allowing 0.0.0.0/0 on port 22 as non-compliant. When non-compliance is detected, AWS Config can trigger an Amazon SNS notification for immediate alerting, and it retains a compliance history for auditing, which is exactly what the company needs.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is an audit service that records every API call made in the account, including those that modify Network ACL entries, capturing who made the change, when, and from which IP. However, CloudTrail only delivers log files of API activity; it has no built-in logic to evaluate whether the resulting NACL configuration is compliant with security standards. To detect the open inbound SSH rule, you would have to write complex queries against CloudTrail logs, but CloudTrail does not provide native, ongoing configuration compliance assessment.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.