Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer is tasked with ensuring that all S3 buckets in an AWS account have versioning enabled. The engineer needs to identify buckets that do not have versioning enabled. Which AWS service is BEST suited for this task?

⚠ Common exam trap

SCS-C02 often tests the distinction between services that record activity (CloudTrail) and services that evaluate configuration state (AWS Config) — candidates may pick CloudTrail because it logs S3 API calls, but it cannot report on current versioning status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config is the best-suited service because it continuously evaluates resource configurations against desired rules. You can use the managed rule 's3-bucket-versioning-enabled' to identify buckets that do not have versioning enabled, and AWS Config will flag them as non-compliant. This provides an automated, scalable way to audit all buckets in an account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor includes checks such as S3 bucket permissions and logging, but it has no check that evaluates whether versioning is enabled on every bucket. Its security checks are a limited set of best-practice recommendations, not a full configuration-auditing service. Therefore, it cannot enforce or report on S3 versioning status across your account.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity such as PutBucketVersioning calls, but it stores an event log rather than a current configuration state. A CloudTrail event can show that versioning was toggled in the past, but it cannot tell you whether any bucket is versioning-enabled at this moment. Compliance auditing requires a service that compares current resource configurations against rules, which CloudTrail does not do.

  • ✗

    IAM Access Analyzer

    Why it's wrong here

    IAM Access Analyzer analyzes resource-based policies to identify external access to S3 buckets, not the bucket's feature configuration. It evaluates who can access a bucket through its policy, not whether server-side settings such as versioning are enabled. Bucket versioning is a data-protection attribute outside the scope of IAM Access Analyzer's policy-analysis engine, so it would never report a finding for a bucket with versioning disabled.

  • ✓

    AWS Config

    Why this is correct

    AWS Config provides the managed rule 's3-bucket-versioning-enabled' and continuously records S3 bucket configuration items. When a bucket is created or changed, AWS Config evaluates it against the rule and marks it compliant or noncompliant, allowing you to track versioning status over time. This is the correct service because it performs continuous, account-wide configuration compliance evaluation rather than a one-time or policy-focused check.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.