Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses Amazon S3 to store sensitive data. The security team wants to detect and alert on public read access to S3 buckets. Which combination of AWS services is MOST appropriate?

⚠ Common exam trap

A common mix-up: candidates confuse AWS Config's compliance evaluation (which is periodic and reactive) with real-time detection and alerting, or they mistakenly believe CloudTrail captures all public access events, when in fact it only logs API calls that change permissions, not the resulting access state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Macie with automated discovery jobs and Amazon CloudWatch Events to send alerts.

Amazon Macie is purpose-built for discovering and protecting sensitive data in S3, and its automated discovery jobs can detect public read access to buckets. By integrating with Amazon CloudWatch Events, Macie can trigger alerts in real-time when such access is identified, making it the most appropriate choice for this detection and alerting requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail and Amazon CloudWatch Logs with metric filters for `PutBucketPolicy` events.

    Why it's wrong here

    These services provide an audit trail of API activity. A metric filter on `PutBucketPolicy` can alert when a policy is edited, but it does not inspect the policy document for public access grants, nor does it detect buckets already made public before logging was enabled. This is passive, event-based monitoring rather than a security posture assessment.

  • ✓

    Amazon Macie with automated discovery jobs and Amazon CloudWatch Events to send alerts.

    Why this is correct

    Macie automatically discovers sensitive data using managed data identifiers and also evaluates S3 bucket policies and ACLs for public access. It runs automated discovery jobs on a schedule, and you can use CloudWatch Events to trigger alerts for both sensitive data findings and policy findings. This combines content discovery with access control verification, addressing both dimensions of the requirement.

  • ✗

    Amazon GuardDuty and AWS Lambda.

    Why it's wrong here

    GuardDuty analyzes CloudTrail, VPC flow logs, and DNS logs for threats like compromised credentials or malicious activity, but it doesn't evaluate S3 bucket policies or ACLs for public exposure. Moreover, GuardDuty isn't a configuration compliance tool; it would not detect that a policy allows "Everyone" read access unless there is a corresponding finding, which is not the case. Lambda alone could be custom-coded, but this combination is not purpose-built for this need.

  • ✗

    AWS Config with managed rules like `s3-bucket-public-read-prohibited` and Amazon SNS.

    Why it's wrong here

    AWS Config does continuously evaluate S3 bucket configurations against managed rules such as `s3-bucket-public-read-prohibited` and can send SNS notifications when noncompliant. However, Config only assesses the configuration of the bucket—it doesn't analyze the contents of objects for sensitive data, which is central to the requirement. Config can tell you a bucket is publicly readable, but not whether it contains PII or other sensitive data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.