Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company has enabled AWS Config to record resource changes. The security team needs to be notified when a security group is modified to allow inbound SSH from 0.0.0.0/0. Which AWS service should be used to evaluate the Config rules and trigger notifications?

⚠ Common exam trap

Test-takers frequently confuse AWS Config's built-in managed rules (which do not support custom SNS triggers) with the need for a separate service like Lambda or Security Hub, but the correct answer is AWS Config with a custom rule that directly integrates SNS notifications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config with a custom rule that triggers an SNS notification

AWS Config with a custom rule is the correct choice because it allows you to define a custom Lambda-backed rule that evaluates security group configurations against the condition of allowing inbound SSH (port 22) from 0.0.0.0/0. When the rule detects non-compliance, it can directly trigger an Amazon SNS notification to alert the security team. This is the native AWS Config mechanism for custom evaluations and notifications, without requiring additional services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Lambda

    Why it's wrong here

    AWS Lambda is serverless compute that runs code in response to events such as an S3 object upload or an API Gateway request. It can serve as a remediation tool or as the runtime for a custom AWS Config rule, but it has no native mechanism to assess or record resource configuration compliance. By itself, Lambda cannot determine whether a change made a resource noncompliant with organizational policies, so it cannot be the primary evaluation service.

  • ✗

    AWS Security Hub

    Why it's wrong here

    AWS Security Hub is a cloud security posture management service that aggregates and prioritizes security findings from services like GuardDuty, Inspector, and Firewall Manager across an AWS environment. It can display noncompliant Config rules through an integration, but it does not run compliance evaluations; the underlying Config service performs that evaluation. Enabling Security Hub alone will not record resource changes or assess whether those changes violate Config rules.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a machine-learning-based threat detection service that analyzes data sources such as AWS CloudTrail management events, VPC Flow Logs, and DNS query logs. It identifies threats like malicious IP addresses or unusual API call patterns, but it is not designed to check whether a resource's configuration matches a desired policy. GuardDuty findings relate to active security threats, whereas configuration compliance is a state-based assessment handled by AWS Config.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records the API activity in an account, capturing the who-what-when of actions such as creating an S3 bucket or modifying an IAM role. It does not maintain the resulting resource configuration state, nor does it compare that state against a compliance policy. While CloudTrail can help audit what changed, AWS Config is required to evaluate the configuration after the change and notify when it is noncompliant.

  • ✓

    AWS Config with a custom rule that triggers an SNS notification

    Why this is correct

    AWS Config records resource configuration changes and can evaluate those changes against rules that define desired configurations. A custom rule implemented as a Lambda function returns a compliance status based on a configuration item, and AWS Config can publish the result to an SNS topic when a resource becomes noncompliant. This combination enables real-time notification and corrective workflow each time a configuration change occurs, which is exactly what the requirement needs.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.