Courseiva

SCS-C02 AWS Config Practice Question

A security engineer is designing a system to centrally manage security rules across multiple AWS accounts. The engineer wants to ensure that any resources that are non-compliant with security policies are automatically remediated. Which combination of services should the engineer use?

⚠ Common exam trap

SCS-C02 often tests the distinction between detection/aggregation services (Security Hub, GuardDuty, CloudTrail) and the only service that natively evaluates configuration compliance and can trigger automatic remediation (AWS Config with Lambda/SSM Automation) — candidates frequently pick Security Hub with EventBridge because it sounds like centralized compliance management, but it lacks built-in remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config with AWS Lambda for automatic remediation

AWS Config continuously evaluates resource configurations against desired policies (Config Rules), and its remediation action feature can invoke an AWS Lambda function automatically when a resource is found non-compliant. This combination provides both centralized, multi-account compliance evaluation (via a Config aggregator) and automated remediation, which is exactly what the question requires. Lambda gives the custom logic needed to fix the non-compliant resource, making this the only option that delivers automatic remediation based on compliance state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail with Amazon SNS

    Why it's wrong here

    AWS CloudTrail records API activity across an account, but it does not evaluate resource configurations against compliance standards such as CIS or PCI DSS. Amazon SNS can only publish notifications about those raw API events; it has no logic to assess whether a resource is compliant or to execute a corrective action. This combination provides an audit trail and alerting, not continuous compliance evaluation or automated remediation.

  • ✗

    Amazon GuardDuty with AWS Step Functions

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that identifies malicious activity, unauthorized behavior, and anomalies using threat intelligence and machine learning. AWS Step Functions can orchestrate response workflows, but only after GuardDuty generates a finding; they cannot inspect resource properties or determine whether a configuration drifts from a required standard. This architecture addresses security threats, not configuration compliance, so it does not meet the requirement for central compliance management and remediation.

  • ✗

    AWS Security Hub with Amazon EventBridge

    Why it's wrong here

    AWS Security Hub aggregates findings from services like GuardDuty, Inspector, and AWS Config into a central view, and Amazon EventBridge can route those findings to targets for actions. However, Security Hub itself does not evaluate resource configurations, and EventBridge merely transports events; neither performs the actual remediation. To automatically fix noncompliant resources, Security Hub would still depend on downstream services such as AWS Config rules invoking Lambda, so this option is incomplete on its own.

  • ✓

    AWS Config with AWS Lambda for automatic remediation

    Why this is correct

    AWS Config continuously records resource configuration changes and evaluates them against managed or custom rules to determine compliance. When a resource drifts from the required policy, AWS Config can invoke an AWS Lambda function as a remediation action, which can automatically apply corrective changes such as updating security groups, enabling encryption, or deleting orphaned resources. This combination provides both the compliance evaluation and the automatic remediation needed for a central management system, making it the correct choice.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.