SCS-C02 Management and Security Governance Practice Question
A company needs to ensure that its S3 buckets are not publicly accessible. Which TWO AWS services can be used to detect and report on public S3 buckets? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse Amazon GuardDuty's threat detection capabilities with S3 bucket policy auditing, but GuardDuty does not evaluate bucket permissions for public access; it only detects suspicious API activity after the fact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Trusted Advisor
AWS Trusted Advisor (option B) checks S3 bucket permissions and reports any bucket that has open access policies, including public read or write access. AWS Config (option C) can evaluate S3 bucket policies against custom or managed rules (e.g., s3-bucket-public-read-prohibited, s3-bucket-public-write-prohibited) to detect noncompliant buckets and trigger remediation. Both services provide detection and reporting capabilities for public S3 buckets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a continuous security monitoring service that uses machine learning and integrated threat intelligence to detect anomalous activity, such as compromised credentials or crypto-mining, by analyzing AWS logs including VPC Flow Logs, DNS query logs, and CloudTrail event data. It does not evaluate the configuration state of S3 buckets, so it cannot determine whether a bucket policy or ACL grants public access. While GuardDuty may alert on suspicious S3 operations, it is not the appropriate service for identifying publicly exposed buckets.
- ✓
AWS Trusted Advisor
Why this is correct
AWS Trusted Advisor includes the 'S3 Bucket Permissions' check, which specifically reviews S3 bucket policies and ACLs for configurations that allow public read or write access, and flags those buckets in the Security category of the dashboard. This is a prescriptive, AWS-managed check that immediately identifies public buckets across your account. The check also differentiates between public access granted by ACLs versus bucket policies, providing focused remediation guidance and making it a first-line tool for this requirement.
- ✓
AWS Config
Why this is correct
AWS Config is a fully managed service that records resource configuration changes and evaluates them against rules you define, such as the managed rules s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited. Once configured, AWS Config continuously evaluates the compliance state of each S3 bucket, identifies noncompliant buckets, and can trigger automated remediation actions via Systems Manager Automation. Unlike Trusted Advisor's regular but non-continuous check, AWS Config provides a historical audit trail and ongoing enforcement of your public-access policies.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is an auditing service that records API activity in your account, including PutBucketPolicy or PutBucketAcl API calls that could make a bucket public. However, CloudTrail does not inspect the resulting bucket configuration; it only provides an event history of who made changes, when, and from what source IP. To determine whether a bucket is currently public, you need a service that evaluates the existing resource policy—not a log of past API operations.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is designed for vulnerability management of compute resources, performing automated security assessments of EC2 instances and Amazon ECR container images for software vulnerabilities and unintended network exposure, such as open ports. It has no visibility into S3 bucket policies, ACLs, or S3 access controls. Although publicly accessible S3 buckets are a security risk, Inspector does not evaluate them and therefore cannot be used to enforce this requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.