Courseiva

SCS-C02 Management and Security Governance Practice Question

A company wants to automate the enforcement of security best practices across all AWS accounts in an organization. The solution should automatically remediate noncompliant resources. Which AWS service should be used to achieve this?

⚠ Common exam trap

The trap is confusing preventive controls (SCPs) with detective-and-remediative controls (Config rules); the question's keyword 'automatically remediate' rules out SCPs, which only block actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config rules with auto-remediation

AWS Config rules evaluate resource configurations against desired states and can trigger automatic remediation via SSM Automation documents when a resource is noncompliant. With AWS Organizations integration, Config can aggregate compliance across all accounts and apply remediation centrally, making it the correct choice for automated enforcement with remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Organizations service control policies (SCPs)

    Why it's wrong here

    AWS Organizations service control policies (SCPs) are preventive guardrails that restrict the maximum permissions for all IAM principals in member accounts. They do not actively monitor or correct ongoing configuration drift; they only block actions at the API level before they occur. Because the use case demands automatic remediation of already-noncompliant resources, SCPs cannot fulfill the enforcement loop.

  • ✗

    AWS IAM Access Analyzer

    Why it's wrong here

    AWS IAM Access Analyzer is designed to analyze resource policies and flag potential external access, such as publicly exposed S3 buckets, by generating findings. It is a detective tool for policy visibility, not a compliance automation service that can modify resources or apply corrective actions. It does not continuously evaluate every security best practice nor remediate noncompliant configurations automatically.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that uses machine learning and anomaly detection to identify suspicious activity, such as malicious API calls or crypto mining, and produce security findings. It does not assess compliance against configuration best practices like encryption or logging, and it cannot alter resource settings as a remediation step. Its purpose is to alert on threats, not to enforce or correct misconfigurations.

  • ✓

    AWS Config rules with auto-remediation

    Why this is correct

    AWS Config rules evaluate resource configurations against desired policies and, when a rule is noncompliant, can trigger an associated AWS Systems Manager Automation runbook to automatically perform the necessary corrective action. This combination of continuous evaluation and auto-remediation directly addresses the need to automate enforcement of security best practices. For example, a Config rule can detect an S3 bucket without encryption and invoke an Automation document to enable default encryption, all without manual intervention.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.