Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer is designing a solution to automatically remediate non-compliant resources in an AWS account. The engineer needs to trigger an AWS Lambda function when an EC2 instance is launched without the required tags. Which AWS service should be used to detect the non-compliant resource and invoke the Lambda function?

⚠ Common exam trap

SCS-C02 often tests the difference between detection services (GuardDuty, CloudTrail) and compliance evaluation services (AWS Config), and candidates may confuse CloudTrail's logging with Config's compliance monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config is the correct service because it continuously evaluates resource configurations against desired rules. You can create a Config rule that checks for required tags on EC2 instances; when a non-compliant instance is detected, Config can automatically invoke a Lambda function via an remediation action. This native integration enables automatic, event-driven remediation without custom polling or additional services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records AWS API activity as a management event history, giving you an audit trail of who made which calls, when, and from where. Because it is a log of past actions, it does not continuously evaluate the current configuration state of resources like whether tags exist, and it has no built-in mechanism to trigger automatic remediation when a required tag is missing. It answers 'what happened,' not 'what is noncompliant right now.'

  • ✓

    AWS Config

    Why this is correct

    AWS Config continuously records resource configurations and evaluates them against managed or custom rules, such as the required-tags rule that checks for specific tag keys. When a resource becomes noncompliant, Config can invoke remediation actions via Systems Manager Automation documents or Lambda functions, such as adding the missing tag automatically. This makes it the correct service for both detecting missing tags and automating their correction.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a security monitoring service that uses machine learning and threat intelligence to detect anomalous behavior and potential threats like compromised credentials, malware, or suspicious API calls. It does not inventory resource metadata or enforce tagging standards, so it would not be able to detect a missing tag on an EC2 instance or S3 bucket. GuardDuty reacts to threats, not configuration compliance.

  • ✗

    AWS Systems Manager

    Why it's wrong here

    AWS Systems Manager is primarily an operations and management service, providing capabilities like Run Command, Patch Manager, and Automation to manage instances and AWS resources at scale. While Systems Manager Automation can be used as part of a remediation workflow, the service itself does not evaluate resources against tag policies or identify noncompliant tags on its own. Therefore, it is not the service that triggers the initial detection of missing tags; it may only execute the fix once a separate service like Config identifies the problem.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.