SCS-C02 Management and Security Governance Practice Question
A security engineer is designing a system to detect and respond to IAM policy changes that could grant excessive permissions. The solution must alert within minutes of the change and automatically revert the change if it violates a predefined baseline. Which combination of services should the engineer use?
⚠ Common exam trap
SCS-C02 often tests the misconception that AWS Config can automatically remediate without additional services, or that CloudTrail alone can trigger actions, ignoring the need for EventBridge and Lambda.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail, Amazon CloudWatch Events, and AWS Lambda
AWS CloudTrail logs IAM policy changes. Amazon CloudWatch Events (now EventBridge) can match specific API calls (e.g., PutRolePolicy) and trigger an AWS Lambda function within minutes. The Lambda function can evaluate the change against a baseline and automatically revert it if it violates the policy, providing both detection and remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail and Amazon S3
Why it's wrong here
CloudTrail records API activity and writes log files to S3, which serves as durable storage and audit evidence. However, S3 buckets are passive objects: they do not evaluate the contents, detect threats, or run any remediation action. Without a separate event-driven service such as Lambda or EventBridge, the logs sit idle until manually reviewed, so this combination cannot meet the 'detect and respond' requirement.
- ✓
AWS CloudTrail, Amazon CloudWatch Events, and AWS Lambda
Why this is correct
CloudTrail continuously streams API activity from the account, and a CloudWatch Events rule can match specific IAM actions (e.g., PutUserPolicy, AttachUserPolicy) in real time. The rule triggers a Lambda function, which can immediately respond by removing the policy, restoring a backup, or alerting security personnel. This is a native, serverless, event-driven architecture that satisfies both detection and automated remediation.
- ✗
AWS Config and AWS Systems Manager
Why it's wrong here
AWS Config continuously records configuration changes and evaluates them against rules, but its periodic evaluations and configuration item notifications are not designed for real-time API-call detection. While Systems Manager Automation documents can remediate resources, they must be explicitly wired through Config rules or manually triggered, and they do not naturally consume CloudTrail event streams for IAM user actions. This combination cannot natively react the instant an unauthorized IAM API call is made.
- ✗
IAM Access Analyzer and AWS Lambda
Why it's wrong here
IAM Access Analyzer scans resource policies to identify trusts outside your account, which is useful for auditing known external access, but it does not monitor real-time API activity such as PutUserPolicy, nor does it alter permissions. Lambda is a general compute service and, by itself, has no visibility into IAM events unless a source like CloudTrail or EventBridge feeds it. Therefore this pair lacks both the event source and the enforcement logic to automatically remediate unauthorized changes.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.