SCS-C02 Management and Security Governance Practice Question
A company wants to enforce that all S3 buckets are encrypted with SSE-KMS. Which AWS service can be used to automatically remediate non-compliant buckets?
⚠ Common exam trap
Test-takers frequently confuse AWS Config's evaluation and remediation capabilities with AWS CloudTrail's logging and event-driven actions, assuming CloudTrail with CloudWatch Events can automatically fix non-compliance without custom code, but AWS Config is the only service that provides native, automated remediation via managed rules and automation documents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config with auto-remediation
AWS Config with auto-remediation can enforce that all S3 buckets are encrypted with SSE-KMS. You create an AWS Config rule (e.g., s3-bucket-server-side-encryption-enabled) that evaluates bucket encryption settings, and attach an AWS Systems Manager Automation document (e.g., AWS-EnableS3BucketEncryption) as a remediation action. When a non-compliant bucket is detected, AWS Config automatically triggers the remediation action to enable SSE-KMS encryption on that bucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail with CloudWatch Events
Why it's wrong here
AWS CloudTrail with CloudWatch Events is a detective and event-driven control, not an enforcement mechanism. CloudTrail records API activity such as s3:CreateBucket or PutBucketEncryption calls, and CloudWatch Events can route those events to a custom Lambda function, but this combination does not natively inspect or modify bucket encryption state. You would need to build and maintain a custom remediation function, whereas AWS Config provides managed detection and built-in auto-remediation out of the box.
- ✗
AWS Service Catalog
Why it's wrong here
AWS Service Catalog is a governance service for publishing approved AWS service templates and managing portfolios of IT products. Although a CloudFormation template in Service Catalog can include encrypted bucket definitions, it only enforces those settings when resources are provisioned through the catalog. It does not retroactively scan existing S3 buckets and it cannot block or remediate buckets created outside the catalog, so it cannot guarantee encryption across all S3 buckets.
- ✓
AWS Config with auto-remediation
Why this is correct
AWS Config with auto-remediation is the correct choice because it continuously evaluates bucket configuration against a managed rule such as s3-bucket-server-side-encryption-enabled. When a bucket is non-compliant, Config automatically triggers a Systems Manager Automation document, often AWS-EnableS3BucketEncryption, to enable SSE-S3 or SSE-KMS on that bucket. This provides a closed-loop detective-and-remediative workflow that handles both newly created and already-existing unencrypted buckets.
- ✗
AWS Organizations
Why it's wrong here
AWS Organizations provides account hierarchy, consolidated billing, and service control policies (SCPs) that restrict which API actions principals can call. SCPs can deny permissions to disable certain encryption features, but they cannot inspect or mutate a bucket's current encryption configuration. SCPs are preventive permission guardrails at the account or organizational level, not a service that automatically remediates unencrypted S3 buckets after they are created.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.