SCS-C02 Management and Security Governance Practice Question
A company wants to ensure that all S3 buckets in their AWS account have encryption enabled. Which AWS service can continuously evaluate compliance and automatically remediate non-compliant buckets?
⚠ Common exam trap
SCS-C02 often tests the difference between detective and preventive controls; candidates may choose CloudTrail for compliance monitoring, but CloudTrail only logs API calls and does not evaluate compliance or remediate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the service that continuously evaluates resource configurations against desired policies and can automatically remediate non-compliant resources. It can monitor S3 bucket encryption settings and trigger remediation actions (e.g., via SSM Automation) to enable encryption. AWS Config rules can be configured to check for encryption and automatically remediate using remediation actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records S3 API activity such as PutBucketEncryption and PutObject, so it can tell you whether a bucket was ever configured with encryption, but it cannot evaluate the ongoing encryption state of every bucket against a compliance rule. Without an external system that scans configuration, it does not detect a bucket that was created unencrypted or that has been reverted. CloudTrail is an auditing trail, not a compliance enforcement engine.
- ✓
AWS Config
Why this is correct
AWS Config continuously records the configuration of each S3 bucket and evaluates the recorded state against managed rules such as s3-bucket-server-side-encryption-enabled. When a bucket is noncompliant, Config can trigger Auto Remediation via a Systems Manager Automation document to append or modify the bucket's encryption configuration. This works on existing buckets in near-real time, and also on any new bucket created, making it a direct enforcement mechanism.
- ✗
AWS IAM
Why it's wrong here
IAM can restrict who can create or modify buckets, and an IAM policy can require encryption in the API call using the s3:x-amz-server-side-encryption condition key, but IAM does not inspect or repair configurations that already exist. A bucket that was created without default encryption and never receives new writes remains fully noncompliant even with strict IAM policies in place. Thus, IAM controls actions, not current object and bucket encryption posture.
- ✗
Amazon S3
Why it's wrong here
Amazon S3 supports default bucket encryption as a bucket setting, but the service will not automatically switch on that setting for every bucket in an account. An unencrypted bucket can still accept objects and remain noncompliant unless someone changes the bucket's DefaultEncryption configuration or a rule enforces it. So while S3 is the resource being governed, it cannot itself enforce account-wide compliance across all buckets without an external evaluator such as AWS Config.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.