Courseiva

SCS-C02 Management and Security Governance Practice Question

A company wants to ensure that all S3 buckets in their AWS account have encryption enabled. Which AWS service can continuously evaluate compliance and automatically remediate non-compliant buckets?

⚠ Common exam trap

SCS-C02 often tests the difference between detective and preventive controls; candidates may choose CloudTrail for compliance monitoring, but CloudTrail only logs API calls and does not evaluate compliance or remediate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config is the service that continuously evaluates resource configurations against desired policies and can automatically remediate non-compliant resources. It can monitor S3 bucket encryption settings and trigger remediation actions (e.g., via SSM Automation) to enable encryption. AWS Config rules can be configured to check for encryption and automatically remediate using remediation actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail records S3 API activity such as PutBucketEncryption and PutObject, so it can tell you whether a bucket was ever configured with encryption, but it cannot evaluate the ongoing encryption state of every bucket against a compliance rule. Without an external system that scans configuration, it does not detect a bucket that was created unencrypted or that has been reverted. CloudTrail is an auditing trail, not a compliance enforcement engine.

  • ✓

    AWS Config

    Why this is correct

    AWS Config continuously records the configuration of each S3 bucket and evaluates the recorded state against managed rules such as s3-bucket-server-side-encryption-enabled. When a bucket is noncompliant, Config can trigger Auto Remediation via a Systems Manager Automation document to append or modify the bucket's encryption configuration. This works on existing buckets in near-real time, and also on any new bucket created, making it a direct enforcement mechanism.

  • ✗

    AWS IAM

    Why it's wrong here

    IAM can restrict who can create or modify buckets, and an IAM policy can require encryption in the API call using the s3:x-amz-server-side-encryption condition key, but IAM does not inspect or repair configurations that already exist. A bucket that was created without default encryption and never receives new writes remains fully noncompliant even with strict IAM policies in place. Thus, IAM controls actions, not current object and bucket encryption posture.

  • ✗

    Amazon S3

    Why it's wrong here

    Amazon S3 supports default bucket encryption as a bucket setting, but the service will not automatically switch on that setting for every bucket in an account. An unencrypted bucket can still accept objects and remain noncompliant unless someone changes the bucket's DefaultEncryption configuration or a rule enforces it. So while S3 is the resource being governed, it cannot itself enforce account-wide compliance across all buckets without an external evaluator such as AWS Config.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.