SCS-C02 AWS Config Practice Question
A security engineer is designing a system to centrally manage security rules across multiple AWS accounts. The engineer wants to ensure that any resources that are non-compliant with security policies are automatically remediated. Which combination of services should the engineer use?
⚠ Common exam trap
SCS-C02 often tests the distinction between detection/aggregation services (Security Hub, GuardDuty, CloudTrail) and the only service that natively evaluates configuration compliance and can trigger automatic remediation (AWS Config with Lambda/SSM Automation) — candidates frequently pick Security Hub with EventBridge because it sounds like centralized compliance management, but it lacks built-in remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config with AWS Lambda for automatic remediation
AWS Config continuously evaluates resource configurations against desired policies (Config Rules), and its remediation action feature can invoke an AWS Lambda function automatically when a resource is found non-compliant. This combination provides both centralized, multi-account compliance evaluation (via a Config aggregator) and automated remediation, which is exactly what the question requires. Lambda gives the custom logic needed to fix the non-compliant resource, making this the only option that delivers automatic remediation based on compliance state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail with Amazon SNS
Why it's wrong here
AWS CloudTrail records API activity across an account, but it does not evaluate resource configurations against compliance standards such as CIS or PCI DSS. Amazon SNS can only publish notifications about those raw API events; it has no logic to assess whether a resource is compliant or to execute a corrective action. This combination provides an audit trail and alerting, not continuous compliance evaluation or automated remediation.
- ✗
Amazon GuardDuty with AWS Step Functions
Why it's wrong here
Amazon GuardDuty is a threat detection service that identifies malicious activity, unauthorized behavior, and anomalies using threat intelligence and machine learning. AWS Step Functions can orchestrate response workflows, but only after GuardDuty generates a finding; they cannot inspect resource properties or determine whether a configuration drifts from a required standard. This architecture addresses security threats, not configuration compliance, so it does not meet the requirement for central compliance management and remediation.
- ✗
AWS Security Hub with Amazon EventBridge
Why it's wrong here
AWS Security Hub aggregates findings from services like GuardDuty, Inspector, and AWS Config into a central view, and Amazon EventBridge can route those findings to targets for actions. However, Security Hub itself does not evaluate resource configurations, and EventBridge merely transports events; neither performs the actual remediation. To automatically fix noncompliant resources, Security Hub would still depend on downstream services such as AWS Config rules invoking Lambda, so this option is incomplete on its own.
- ✓
AWS Config with AWS Lambda for automatic remediation
Why this is correct
AWS Config continuously records resource configuration changes and evaluates them against managed or custom rules to determine compliance. When a resource drifts from the required policy, AWS Config can invoke an AWS Lambda function as a remediation action, which can automatically apply corrective changes such as updating security groups, enabling encryption, or deleting orphaned resources. This combination provides both the compliance evaluation and the automatic remediation needed for a central management system, making it the correct choice.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.