Courseiva

SCS-C02 Management and Security Governance Practice Question

A company needs to ensure that its S3 buckets are not publicly accessible. Which TWO AWS services can be used to detect and report on public S3 buckets? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse Amazon GuardDuty's threat detection capabilities with S3 bucket policy auditing, but GuardDuty does not evaluate bucket permissions for public access; it only detects suspicious API activity after the fact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Trusted Advisor

AWS Trusted Advisor (option B) checks S3 bucket permissions and reports any bucket that has open access policies, including public read or write access. AWS Config (option C) can evaluate S3 bucket policies against custom or managed rules (e.g., s3-bucket-public-read-prohibited, s3-bucket-public-write-prohibited) to detect noncompliant buckets and trigger remediation. Both services provide detection and reporting capabilities for public S3 buckets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a continuous security monitoring service that uses machine learning and integrated threat intelligence to detect anomalous activity, such as compromised credentials or crypto-mining, by analyzing AWS logs including VPC Flow Logs, DNS query logs, and CloudTrail event data. It does not evaluate the configuration state of S3 buckets, so it cannot determine whether a bucket policy or ACL grants public access. While GuardDuty may alert on suspicious S3 operations, it is not the appropriate service for identifying publicly exposed buckets.

  • ✓

    AWS Trusted Advisor

    Why this is correct

    AWS Trusted Advisor includes the 'S3 Bucket Permissions' check, which specifically reviews S3 bucket policies and ACLs for configurations that allow public read or write access, and flags those buckets in the Security category of the dashboard. This is a prescriptive, AWS-managed check that immediately identifies public buckets across your account. The check also differentiates between public access granted by ACLs versus bucket policies, providing focused remediation guidance and making it a first-line tool for this requirement.

  • ✓

    AWS Config

    Why this is correct

    AWS Config is a fully managed service that records resource configuration changes and evaluates them against rules you define, such as the managed rules s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited. Once configured, AWS Config continuously evaluates the compliance state of each S3 bucket, identifies noncompliant buckets, and can trigger automated remediation actions via Systems Manager Automation. Unlike Trusted Advisor's regular but non-continuous check, AWS Config provides a historical audit trail and ongoing enforcement of your public-access policies.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is an auditing service that records API activity in your account, including PutBucketPolicy or PutBucketAcl API calls that could make a bucket public. However, CloudTrail does not inspect the resulting bucket configuration; it only provides an event history of who made changes, when, and from what source IP. To determine whether a bucket is currently public, you need a service that evaluates the existing resource policy—not a log of past API operations.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is designed for vulnerability management of compute resources, performing automated security assessments of EC2 instances and Amazon ECR container images for software vulnerabilities and unintended network exposure, such as open ports. It has no visibility into S3 bucket policies, ACLs, or S3 access controls. Although publicly accessible S3 buckets are a security risk, Inspector does not evaluate them and therefore cannot be used to enforce this requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.