SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer needs to ensure that any changes to an S3 bucket's public access settings are immediately detected and an alert is sent. Which combination of AWS services should be used?
⚠ Common exam trap
Many exam-takers confuse AWS CloudTrail (which logs API calls) with AWS Config (which evaluates configuration compliance), leading them to choose Option C, but CloudTrail alone cannot trigger alerts without additional services like CloudWatch Logs and Lambda, and it lacks the continuous compliance evaluation that AWS Config provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config and AWS Lambda
AWS Config continuously monitors and records changes to AWS resource configurations, including S3 bucket public access settings. By creating a Config rule that triggers on changes to the `PublicAccessBlockConfiguration` or bucket ACLs, you can invoke an AWS Lambda function via an Amazon SNS topic to send an alert. This combination provides real-time detection and automated response to unauthorized public access changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty and AWS Lambda
Why it's wrong here
Amazon GuardDuty continuously analyzes AWS CloudTrail management events, VPC flow logs, and DNS logs to identify malicious activity and unauthorized behavior. While GuardDuty can produce findings related to compromised credentials or suspicious API calls, it does not track the state of S3 bucket policies or public access settings, so its event stream would not be the trigger source for a Lambda function in this scenario.
- ✗
Amazon CloudWatch Logs and Amazon SNS
Why it's wrong here
Amazon CloudWatch Logs stores and analyzes log data, while Amazon SNS provides message delivery and notifications. Even combined, they cannot independently evaluate S3 bucket public access configuration because neither service is monitoring bucket policy state; CloudWatch Logs would need to ingest logs that already contain the configuration change, and SNS would only fan out notifications without any actual assessment logic.
- ✗
AWS CloudTrail and Amazon CloudWatch Logs
Why it's wrong here
AWS CloudTrail records every API call made to resources, including PutBucketPolicy and PutPublicAccessBlock, and CloudWatch Logs can receive those logs for metric filtering and alarm evaluation. However, a CloudTrail event only shows that an action occurred, not whether the resulting bucket state is compliant with a security standard, so filtering API calls lacks the context needed to detect a bucket that is effectively public. AWS Config's rules are designed for that state-based evaluation.
- ✓
AWS Config and AWS Lambda
Why this is correct
AWS Config natively tracks configuration items for S3 buckets and applies managed rules such as s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited to flag noncompliant public access settings. When a change makes a bucket noncompliant, Config can invoke an AWS Lambda function through an SNS topic or a custom rule, allowing the Lambda to send an alert or automatically remediate the issue. This pairing provides the state-based monitoring and action-taking pipeline the requirement asks for.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.