SCS-C02 Management and Security Governance Practice Question
A company wants to use AWS CloudFormation to manage infrastructure. The security team requires that all templates are scanned for security vulnerabilities before deployment. Which service should be integrated into the pipeline?
⚠ Common exam trap
Candidates often confuse runtime vulnerability scanning (Amazon Inspector) with pre-deployment template validation (CloudFormation Guard), leading candidates to choose Inspector because they associate 'security vulnerabilities' with runtime scanning rather than infrastructure-as-code compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudFormation Guard
AWS CloudFormation Guard (cfn-guard) is a policy-as-code tool that allows you to define rules to validate CloudFormation templates against security best practices before deployment. It integrates into CI/CD pipelines to enforce compliance with organizational policies, such as ensuring encryption is enabled or public access is restricted, directly addressing the requirement to scan templates for security vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that scans deployed compute resources—EC2 instances, Amazon ECR container images, and Lambda functions—for software vulnerabilities and unintended network exposure. It operates on running workloads, not on infrastructure-as-code artifacts, so it cannot parse a CloudFormation template or evaluate its security policy before provisioning. Thus, while Inspector provides runtime security findings, it is not a pre-deployment template validation tool.
- ✓
AWS CloudFormation Guard
Why this is correct
AWS CloudFormation Guard is the correct choice because it is a policy-as-code engine designed to validate CloudFormation templates (and JSON/YAML in general) against custom rules before deployment. You define guards, such as 'every S3 bucket must have encryption enabled' or 'no IAM user with administrator access', and the Guard CLI or CI/CD integration checks the template's structure and properties. Any noncompliant resource is flagged in the pre-deployment phase, letting you fail the pipeline before infrastructure is created.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service that records resource configurations and continuously evaluates them against desired policies after deployment. It offers managed rules, custom Lambda rules, configuration history, and compliance dashboards, but its evaluation is triggered by configuration changes to existing resources, not by a static analysis of CloudFormation templates. Consequently, Config cannot prevent a noncompliant template from being deployed; it can only detect that a live resource violates a rule afterward.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced is a managed DDoS mitigation service that protects internet-facing applications from volumetric, state-exhaustion, and application-layer attacks, typically in conjunction with CloudFront, Application Load Balancers, and Global Accelerator. Its features include traffic monitoring, attack cost protection, and access to the DDoS Response Team, but it has no mechanism to inspect or validate infrastructure-as-code definitions. Therefore it is entirely unrelated to CloudFormation template governance or policy enforcement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.