SCS-C02 Management and Security Governance Practice Question
A security engineer is designing a solution to monitor and remediate non-compliant resources across multiple AWS accounts. The company uses AWS Organizations and wants to enforce that any S3 bucket with public read access is automatically remediated. The solution must be centralized and scalable. Which approach should the engineer take?
⚠ Common exam trap
It's easy for candidates to confuse conformance packs with simple AWS Config rules, forgetting that conformance packs can include automated remediation actions via Systems Manager Automation, while standalone rules only detect and report non-compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy an AWS Config conformance pack with a rule and an auto-remediation action using AWS Systems Manager Automation.
AWS Config conformance packs allow you to deploy a collection of AWS Config rules and remediation actions across multiple accounts and Regions in AWS Organizations. By including an auto-remediation action using AWS Systems Manager Automation, the solution can automatically remediate S3 buckets with public read access in a centralized and scalable manner, without manual intervention or per-account configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy an AWS Config conformance pack with a rule and an auto-remediation action using AWS Systems Manager Automation.
Why this is correct
AWS Config conformance packs aggregate a pack of rules plus associated remediation actions, deployable across an entire AWS Organization from a single managed template. For a public S3 bucket, the included rule (e.g., s3-bucket-public-read-prohibited) detects noncompliance and automatically invokes an SSM Automation document, such as AWS-DisablePublicReadAccessForS3Bucket, to remove public access. This provides centralized, scalable, and fully automated governance rather than per-account, manual, or report-only controls.
- ✗
Create an AWS Config rule in each account and configure an Amazon CloudWatch Events rule to trigger an AWS Lambda function for remediation.
Why it's wrong here
This approach is inherently fragmented: the engineer would need to install the AWS Config rule, an IAM role, and a CloudWatch Events rule (now Amazon EventBridge) in every account and region, with no single control plane to enforce consistency. While Lambda could perform remediation, this custom, duplicated plumbing increases operational overhead and drift risk; it also lacks the pre-built, auditable remediation orchestration that a conformance pack with SSM Automation provides. For organization-wide monitoring, this is a maintenance burden, not a centralized solution.
- ✗
Use AWS Trusted Advisor to identify public buckets and manually remediate them.
Why it's wrong here
Trusted Advisor's S3 bucket permission checks can flag publicly accessible buckets, but it provides only a recommendation dashboard and cannot change permissions or trigger automated workflows. The engineer would still have to review each finding and remediate by hand, and there is no continuous enforcement if new public buckets are created later. Because this option contains no automation, it fails the stated design goal.
- ✗
Deploy an AWS Config conformance pack with a rule that checks for public buckets and reports non-compliance.
Why it's wrong here
Although this conformance pack rule would evaluate S3 buckets against the public-access policy and report noncompliance, its scope is limited to detection and status reporting. It does not specify any remediation action, such as an SSM Automation document, so public buckets remain exposed indefinitely until a human intervenes. Since the requirement explicitly asks for remediation, a report-only rule is insufficient.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.