Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer is designing a solution to monitor and remediate non-compliant resources across multiple AWS accounts. The company uses AWS Organizations and wants to enforce that any S3 bucket with public read access is automatically remediated. The solution must be centralized and scalable. Which approach should the engineer take?

⚠ Common exam trap

It's easy for candidates to confuse conformance packs with simple AWS Config rules, forgetting that conformance packs can include automated remediation actions via Systems Manager Automation, while standalone rules only detect and report non-compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy an AWS Config conformance pack with a rule and an auto-remediation action using AWS Systems Manager Automation.

AWS Config conformance packs allow you to deploy a collection of AWS Config rules and remediation actions across multiple accounts and Regions in AWS Organizations. By including an auto-remediation action using AWS Systems Manager Automation, the solution can automatically remediate S3 buckets with public read access in a centralized and scalable manner, without manual intervention or per-account configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy an AWS Config conformance pack with a rule and an auto-remediation action using AWS Systems Manager Automation.

    Why this is correct

    AWS Config conformance packs aggregate a pack of rules plus associated remediation actions, deployable across an entire AWS Organization from a single managed template. For a public S3 bucket, the included rule (e.g., s3-bucket-public-read-prohibited) detects noncompliance and automatically invokes an SSM Automation document, such as AWS-DisablePublicReadAccessForS3Bucket, to remove public access. This provides centralized, scalable, and fully automated governance rather than per-account, manual, or report-only controls.

  • ✗

    Create an AWS Config rule in each account and configure an Amazon CloudWatch Events rule to trigger an AWS Lambda function for remediation.

    Why it's wrong here

    This approach is inherently fragmented: the engineer would need to install the AWS Config rule, an IAM role, and a CloudWatch Events rule (now Amazon EventBridge) in every account and region, with no single control plane to enforce consistency. While Lambda could perform remediation, this custom, duplicated plumbing increases operational overhead and drift risk; it also lacks the pre-built, auditable remediation orchestration that a conformance pack with SSM Automation provides. For organization-wide monitoring, this is a maintenance burden, not a centralized solution.

  • ✗

    Use AWS Trusted Advisor to identify public buckets and manually remediate them.

    Why it's wrong here

    Trusted Advisor's S3 bucket permission checks can flag publicly accessible buckets, but it provides only a recommendation dashboard and cannot change permissions or trigger automated workflows. The engineer would still have to review each finding and remediate by hand, and there is no continuous enforcement if new public buckets are created later. Because this option contains no automation, it fails the stated design goal.

  • ✗

    Deploy an AWS Config conformance pack with a rule that checks for public buckets and reports non-compliance.

    Why it's wrong here

    Although this conformance pack rule would evaluate S3 buckets against the public-access policy and report noncompliance, its scope is limited to detection and status reporting. It does not specify any remediation action, such as an SSM Automation document, so public buckets remain exposed indefinitely until a human intervenes. Since the requirement explicitly asks for remediation, a report-only rule is insufficient.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.