SCS-C02 Threat Detection and Incident Response Practice Question
A company's security policy requires that all S3 buckets be encrypted at rest. An security engineer needs to detect any S3 bucket that does not have default encryption enabled. Which AWS service should the engineer use to continuously monitor and alert on non-compliant buckets?
⚠ Common exam trap
It's easy for candidates to confuse AWS CloudTrail (which logs API calls) with AWS Config (which evaluates resource configurations), leading them to choose CloudTrail for monitoring encryption settings when it only records the actions that change encryption, not the current state of encryption on each bucket.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it provides continuous monitoring and evaluation of your AWS resource configurations against desired policies. You can create an AWS Config rule, such as the managed rule 's3-bucket-default-encryption-enabled', which automatically checks each S3 bucket for the presence of default encryption (SSE-S3 or SSE-KMS) and triggers an alert or remediation action for any non-compliant bucket. This aligns directly with the requirement to detect and alert on buckets lacking encryption at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail logs API calls, not the current state of encryption.
- ✓
AWS Config
Why this is correct
Config can continuously evaluate resource configurations and trigger notifications for non-compliant resources.
- ✗
AWS Trusted Advisor
Why it's wrong here
Trusted Advisor provides a point-in-time check, not continuous monitoring and alerts.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty focuses on threat detection, not configuration compliance.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 376 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.