SCS-C02 AWS Config Practice Question
A company has an AWS account with a single VPC and multiple subnets. The security team wants to ensure that no network ACL (NACL) allows inbound SSH (port 22) from 0.0.0.0/0. Which AWS service can be used to detect and alert on such non-compliant NACLs?
⚠ Common exam trap
SCS-C02 often tests the distinction between detection services (GuardDuty for threats, Inspector for vulnerabilities) and compliance evaluation services (Config for configuration rules), tempting candidates to pick GuardDuty for configuration issues.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config continuously records resource configurations and evaluates them against rules, making it the correct service to detect non-compliant NACLs. You can use the managed rule 'nacl-no-unrestricted-ssh-rdp' (or a custom rule) to flag any NACL that allows inbound SSH from 0.0.0.0/0 and trigger alerts via Amazon EventBridge or SNS. This directly addresses the requirement to detect and alert on non-compliant NACLs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is an automated vulnerability management service that uses an agent installed on EC2 instances to assess software-level weaknesses (CVEs) and unintentional network exposure. Its Network Reachability checks analyze instance network paths, but they do not inspect the NACL configuration itself as a resource. Thus Inspector cannot flag a NACL entry permitting inbound SSH from 0.0.0.0/0 as a static compliance violation; it operates on runtime instance findings, not declarative configuration policy.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that ingests VPC Flow Logs, DNS query logs, and CloudTrail event history to identify malicious activity like anomalous SSH brute-force attempts or crypto mining. It relies on observed behavior and threat intelligence to generate findings, rather than on an expected configuration policy. Since a NACL rule permitting SSH from 0.0.0.0/0 is a static network configuration, GuardDuty will not flag it unless it correlates with actual suspicious traffic, making it unsuitable for proactive compliance evaluation.
- ✓
AWS Config
Why this is correct
AWS Config continuously records the configuration of supported resources, including Network ACLs and their inbound/outbound rules, as configuration items in a timeline. It then evaluates those config items against managed rules—such as the managed rule 'incoming-ssh-disabled'—or custom Lambda rules that can inspect each NACL entry and mark any ingress rule allowing 0.0.0.0/0 on port 22 as non-compliant. When non-compliance is detected, AWS Config can trigger an Amazon SNS notification for immediate alerting, and it retains a compliance history for auditing, which is exactly what the company needs.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is an audit service that records every API call made in the account, including those that modify Network ACL entries, capturing who made the change, when, and from which IP. However, CloudTrail only delivers log files of API activity; it has no built-in logic to evaluate whether the resulting NACL configuration is compliant with security standards. To detect the open inbound SSH rule, you would have to write complex queries against CloudTrail logs, but CloudTrail does not provide native, ongoing configuration compliance assessment.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.