SCS-C02 Management and Security Governance Practice Question
A company wants to automate the enforcement of security best practices across all AWS accounts in an organization. The solution should automatically remediate noncompliant resources. Which AWS service should be used to achieve this?
⚠ Common exam trap
The trap is confusing preventive controls (SCPs) with detective-and-remediative controls (Config rules); the question's keyword 'automatically remediate' rules out SCPs, which only block actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config rules with auto-remediation
AWS Config rules evaluate resource configurations against desired states and can trigger automatic remediation via SSM Automation documents when a resource is noncompliant. With AWS Organizations integration, Config can aggregate compliance across all accounts and apply remediation centrally, making it the correct choice for automated enforcement with remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Organizations service control policies (SCPs)
Why it's wrong here
AWS Organizations service control policies (SCPs) are preventive guardrails that restrict the maximum permissions for all IAM principals in member accounts. They do not actively monitor or correct ongoing configuration drift; they only block actions at the API level before they occur. Because the use case demands automatic remediation of already-noncompliant resources, SCPs cannot fulfill the enforcement loop.
- ✗
AWS IAM Access Analyzer
Why it's wrong here
AWS IAM Access Analyzer is designed to analyze resource policies and flag potential external access, such as publicly exposed S3 buckets, by generating findings. It is a detective tool for policy visibility, not a compliance automation service that can modify resources or apply corrective actions. It does not continuously evaluate every security best practice nor remediate noncompliant configurations automatically.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that uses machine learning and anomaly detection to identify suspicious activity, such as malicious API calls or crypto mining, and produce security findings. It does not assess compliance against configuration best practices like encryption or logging, and it cannot alter resource settings as a remediation step. Its purpose is to alert on threats, not to enforce or correct misconfigurations.
- ✓
AWS Config rules with auto-remediation
Why this is correct
AWS Config rules evaluate resource configurations against desired policies and, when a rule is noncompliant, can trigger an associated AWS Systems Manager Automation runbook to automatically perform the necessary corrective action. This combination of continuous evaluation and auto-remediation directly addresses the need to automate enforcement of security best practices. For example, a Config rule can detect an S3 bucket without encryption and invoke an Automation document to enable default encryption, all without manual intervention.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.