Courseiva

SCS-C02 Management and Security Governance Practice Question

A company wants to automatically detect and notify about any S3 buckets that have public read access. Which combination of services should be used?

⚠ Common exam trap

SCS-C02 often tests the distinction between services that log activity (CloudTrail) versus services that evaluate configuration state (Config) — candidates frequently pick CloudTrail for detection questions when Config is the correct answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config and Amazon EventBridge

AWS Config continuously records S3 bucket configurations and can evaluate them against managed rules such as 's3-bucket-public-read-prohibited', flagging any bucket with public read access as non-compliant. Amazon EventBridge can then route Config's compliance change events to targets like SNS or Lambda for notification. This combination provides both detection and automated notification without custom code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail and AWS Lambda

    Why it's wrong here

    CloudTrail logs API activity after it occurs, so it records bucket policy changes but does not evaluate whether a bucket currently permits public read access. It is tempting because CloudTrail plus Lambda can react to PutBucketPolicy events, but continuous posture detection requires AWS Config rules and Amazon SNS notifications.

  • ✓

    AWS Config and Amazon EventBridge

    Why this is correct

    AWS Config rules continuously evaluate bucket policies and ACLs, flagging any bucket granting public read access as noncompliant. EventBridge then routes those compliance-change events to a notification target, delivering the automatic detection and alerting the stem requires without polling.

  • ✗

    AWS IAM Access Analyzer and Amazon CloudWatch

    Why it's wrong here

    IAM Access Analyzer identifies resource policies granting external access, but CloudWatch alone does not evaluate bucket ACLs or policy changes for public read exposure. The pairing is tempting because both services are native monitoring tools, and would be correct if the requirement were alerting on metric thresholds rather than detecting public access.

  • ✗

    AWS Trusted Advisor and Amazon SES

    Why it's wrong here

    Trusted Advisor checks are periodic and cover a limited set of common best-practise items, and Amazon SES sends email rather than driving automated detection workflows. It is tempting because Trusted Advisor flags public S3 access, but continuous detection with event-driven notification needs AWS Config rules and Amazon SNS.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.