SCS-C02 Management and Security Governance Practice Question
A company wants to ensure that all Amazon S3 buckets are encrypted at rest. Which THREE services can be used together to automatically remediate unencrypted S3 buckets?
⚠ Common exam trap
SCS-C02 often tests the misconception that CloudTrail or S3 default encryption alone can remediate — the trap is forgetting that Config detects, EventBridge routes, and Lambda acts, forming a three-service chain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon EventBridge
AWS Config (D) is correct because it continuously evaluates S3 bucket configuration against a managed rule such as s3-bucket-server-side-encryption-enabled and flags buckets that are not encrypted at rest. Amazon EventBridge (C) is correct because it can receive the AWS Config compliance-change event (or a Config rule evaluation result) and route it to a target for automated remediation. AWS Lambda (E) is correct because it serves as the remediation target, running code that calls PutBucketEncryption to enable default encryption on the noncompliant bucket. Amazon S3 default encryption (A) is not a remediation mechanism by itself; it only defines encryption applied to objects when the bucket setting is enabled, so it cannot detect or fix an unencrypted bucket. AWS CloudTrail (B) records API activity for auditing but does not evaluate resource compliance or trigger automatic remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon S3 default encryption
Why it's wrong here
Amazon S3 default encryption is a per-bucket setting; it does not automatically detect or remediate unencrypted buckets across all S3 buckets. It is not a service that can be used together with others for automatic remediation.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is incorrect because it is a read-only audit service that records API calls such as CreateBucket, PutBucket, and PutBucketEncryption for security investigation and operational forensics. It cannot evaluate configuration state, detect that a bucket is missing default encryption, or trigger remediation actions; it only provides a historical trail after activity has occurred. Therefore, CloudTrail has no role in the proactive detection-and-remediation loop this architecture requires.
- ✓
Amazon EventBridge
Why this is correct
Amazon EventBridge is the event-routing backbone of the remediation workflow: it receives compliance state-change events published by AWS Config, such as a bucket transitioning to NON_COMPLIANT for the s3-bucket-server-side-encryption-enabled rule. Using an EventBridge rule, you filter for these S3 compliance events and target an AWS Lambda function for automatic response. Without EventBridge, AWS Config would only generate history or console notifications and would not have a native, low-latency path to invoke custom remediation code.
- ✓
AWS Config
Why this is correct
AWS Config performs the ongoing detection: a managed rule like S3_BUCKET_SERVER_SIDE_ENCRYPTION_ENABLED continuously evaluates each S3 bucket against the required encryption setting. When a bucket lacks default encryption, AWS Config marks it NON_COMPLIANT and publishes a configuration snapshot or compliance change event to the default event bus, which EventBridge consumes. This makes AWS Config the authoritative compliance evaluator, not just a log of past actions.
- ✓
AWS Lambda
Why this is correct
AWS Lambda is the remediation executor that receives the EventBridge-triggered event and programmatically repairs the noncompliant bucket by calling PutBucketEncryption with AES256 or aws:kms. The same function can include idempotency checks, retry logic, and alerting via SNS, ensuring buckets are brought back into compliance without manual intervention. In this architecture, Lambda is necessary because neither AWS Config nor EventBridge has built-in permissions or logic to modify S3 bucket encryption settings directly.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.