Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer is designing a system to detect and respond to IAM policy changes that could grant excessive permissions. The solution must alert within minutes of the change and automatically revert the change if it violates a predefined baseline. Which combination of services should the engineer use?

⚠ Common exam trap

SCS-C02 often tests the misconception that AWS Config can automatically remediate without additional services, or that CloudTrail alone can trigger actions, ignoring the need for EventBridge and Lambda.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail, Amazon CloudWatch Events, and AWS Lambda

AWS CloudTrail logs IAM policy changes. Amazon CloudWatch Events (now EventBridge) can match specific API calls (e.g., PutRolePolicy) and trigger an AWS Lambda function within minutes. The Lambda function can evaluate the change against a baseline and automatically revert it if it violates the policy, providing both detection and remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail and Amazon S3

    Why it's wrong here

    CloudTrail records API activity and writes log files to S3, which serves as durable storage and audit evidence. However, S3 buckets are passive objects: they do not evaluate the contents, detect threats, or run any remediation action. Without a separate event-driven service such as Lambda or EventBridge, the logs sit idle until manually reviewed, so this combination cannot meet the 'detect and respond' requirement.

  • ✓

    AWS CloudTrail, Amazon CloudWatch Events, and AWS Lambda

    Why this is correct

    CloudTrail continuously streams API activity from the account, and a CloudWatch Events rule can match specific IAM actions (e.g., PutUserPolicy, AttachUserPolicy) in real time. The rule triggers a Lambda function, which can immediately respond by removing the policy, restoring a backup, or alerting security personnel. This is a native, serverless, event-driven architecture that satisfies both detection and automated remediation.

  • ✗

    AWS Config and AWS Systems Manager

    Why it's wrong here

    AWS Config continuously records configuration changes and evaluates them against rules, but its periodic evaluations and configuration item notifications are not designed for real-time API-call detection. While Systems Manager Automation documents can remediate resources, they must be explicitly wired through Config rules or manually triggered, and they do not naturally consume CloudTrail event streams for IAM user actions. This combination cannot natively react the instant an unauthorized IAM API call is made.

  • ✗

    IAM Access Analyzer and AWS Lambda

    Why it's wrong here

    IAM Access Analyzer scans resource policies to identify trusts outside your account, which is useful for auditing known external access, but it does not monitor real-time API activity such as PutUserPolicy, nor does it alter permissions. Lambda is a general compute service and, by itself, has no visibility into IAM events unless a source like CloudTrail or EventBridge feeds it. Therefore this pair lacks both the event source and the enforcement logic to automatically remediate unauthorized changes.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.