SCS-C02 Infrastructure Security Practice Question
A company is using AWS CloudFormation to deploy a web application. The template includes an EC2 instance with a security group that allows inbound HTTP traffic from 0.0.0.0/0. The security team wants to ensure that this security group is never used in production. Which AWS service can automatically remediate this noncompliant configuration?
⚠ Common exam trap
Candidates often confuse AWS Config's detective and preventive capabilities with those of GuardDuty or CloudTrail, mistakenly thinking that threat detection or logging services can automatically fix misconfigurations, when only AWS Config with remediation actions can do so.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it provides managed rules (e.g., 'restricted-ssh' or 'incoming-ssh-disabled') that can evaluate security group configurations against desired compliance. When a noncompliant resource is detected, AWS Config can trigger an automatic remediation action via Systems Manager Automation documents (e.g., AWSConfigRemediation-RevokeUnusedSecurityGroupIngress) to remove the overly permissive inbound rule. This directly addresses the security team's requirement to prevent the use of a security group allowing HTTP traffic from 0.0.0.0/0 in production.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Identity and Access Management (IAM)
Why it's wrong here
AWS Identity and Access Management (IAM) governs authentication and authorization by defining users, roles, policies, and permissions. It does not evaluate, compare, or restore live resource settings against a declared CloudFormation template, so it cannot detect configuration drift or automatically remediate noncompliant resources. IAM's scope ends at access control, making it an operational prerequisite rather than a configuration governance service.
- ✓
AWS Config
Why this is correct
AWS Config continuously records each supported resource's configuration history and evaluates that state against customizable rules and conformance packs. When a resource violates a rule, Config can invoke an AWS Systems Manager Automation document to perform auto-remediation, such as restoring security group rules or untagging resources. This combination of continuous evaluation and corrective action is exactly what is needed to enforce the intended deployed state from CloudFormation.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that consumes AWS CloudTrail management events, VPC Flow Logs, and DNS query logs to identify malicious activity like compromised credentials or crypto mining. It has no concept of a desired resource template and does not inspect current configuration values for compliance; therefore, it cannot detect configuration drift or trigger a remediation workflow to realign resources with the CloudFormation definition.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records user activity and API calls across your account for auditing and security investigation, retaining who made which change and when. Although searching CloudTrail logs could reveal the action that caused drift, CloudTrail itself never compares current resource properties to a baseline and cannot initiate remedial action. It is a passive audit trail, not an evaluation or remediation engine.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.