SCS-C02 Management and Security Governance Practice Question
A company wants to automatically detect and notify about any S3 buckets that have public read access. Which combination of services should be used?
⚠ Common exam trap
SCS-C02 often tests the distinction between services that log activity (CloudTrail) versus services that evaluate configuration state (Config) — candidates frequently pick CloudTrail for detection questions when Config is the correct answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config and Amazon EventBridge
AWS Config continuously records S3 bucket configurations and can evaluate them against managed rules such as 's3-bucket-public-read-prohibited', flagging any bucket with public read access as non-compliant. Amazon EventBridge can then route Config's compliance change events to targets like SNS or Lambda for notification. This combination provides both detection and automated notification without custom code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail and AWS Lambda
Why it's wrong here
CloudTrail logs API activity after it occurs, so it records bucket policy changes but does not evaluate whether a bucket currently permits public read access. It is tempting because CloudTrail plus Lambda can react to PutBucketPolicy events, but continuous posture detection requires AWS Config rules and Amazon SNS notifications.
- ✓
AWS Config and Amazon EventBridge
Why this is correct
AWS Config rules continuously evaluate bucket policies and ACLs, flagging any bucket granting public read access as noncompliant. EventBridge then routes those compliance-change events to a notification target, delivering the automatic detection and alerting the stem requires without polling.
- ✗
AWS IAM Access Analyzer and Amazon CloudWatch
Why it's wrong here
IAM Access Analyzer identifies resource policies granting external access, but CloudWatch alone does not evaluate bucket ACLs or policy changes for public read exposure. The pairing is tempting because both services are native monitoring tools, and would be correct if the requirement were alerting on metric thresholds rather than detecting public access.
- ✗
AWS Trusted Advisor and Amazon SES
Why it's wrong here
Trusted Advisor checks are periodic and cover a limited set of common best-practise items, and Amazon SES sends email rather than driving automated detection workflows. It is tempting because Trusted Advisor flags public S3 access, but continuous detection with event-driven notification needs AWS Config rules and Amazon SNS.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.