Courseiva

SCS-C02 Management and Security Governance Practice Question

A company wants to enforce that all S3 buckets are encrypted with SSE-KMS. Which AWS service can be used to automatically remediate non-compliant buckets?

⚠ Common exam trap

Test-takers frequently confuse AWS Config's evaluation and remediation capabilities with AWS CloudTrail's logging and event-driven actions, assuming CloudTrail with CloudWatch Events can automatically fix non-compliance without custom code, but AWS Config is the only service that provides native, automated remediation via managed rules and automation documents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config with auto-remediation

AWS Config with auto-remediation can enforce that all S3 buckets are encrypted with SSE-KMS. You create an AWS Config rule (e.g., s3-bucket-server-side-encryption-enabled) that evaluates bucket encryption settings, and attach an AWS Systems Manager Automation document (e.g., AWS-EnableS3BucketEncryption) as a remediation action. When a non-compliant bucket is detected, AWS Config automatically triggers the remediation action to enable SSE-KMS encryption on that bucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail with CloudWatch Events

    Why it's wrong here

    AWS CloudTrail with CloudWatch Events is a detective and event-driven control, not an enforcement mechanism. CloudTrail records API activity such as s3:CreateBucket or PutBucketEncryption calls, and CloudWatch Events can route those events to a custom Lambda function, but this combination does not natively inspect or modify bucket encryption state. You would need to build and maintain a custom remediation function, whereas AWS Config provides managed detection and built-in auto-remediation out of the box.

  • ✗

    AWS Service Catalog

    Why it's wrong here

    AWS Service Catalog is a governance service for publishing approved AWS service templates and managing portfolios of IT products. Although a CloudFormation template in Service Catalog can include encrypted bucket definitions, it only enforces those settings when resources are provisioned through the catalog. It does not retroactively scan existing S3 buckets and it cannot block or remediate buckets created outside the catalog, so it cannot guarantee encryption across all S3 buckets.

  • ✓

    AWS Config with auto-remediation

    Why this is correct

    AWS Config with auto-remediation is the correct choice because it continuously evaluates bucket configuration against a managed rule such as s3-bucket-server-side-encryption-enabled. When a bucket is non-compliant, Config automatically triggers a Systems Manager Automation document, often AWS-EnableS3BucketEncryption, to enable SSE-S3 or SSE-KMS on that bucket. This provides a closed-loop detective-and-remediative workflow that handles both newly created and already-existing unencrypted buckets.

  • ✗

    AWS Organizations

    Why it's wrong here

    AWS Organizations provides account hierarchy, consolidated billing, and service control policies (SCPs) that restrict which API actions principals can call. SCPs can deny permissions to disable certain encryption features, but they cannot inspect or mutate a bucket's current encryption configuration. SCPs are preventive permission guardrails at the account or organizational level, not a service that automatically remediates unencrypted S3 buckets after they are created.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.