SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company has an S3 bucket that stores sensitive data. A SysOps administrator needs to detect when objects in the bucket are publicly accessible. Which AWS service should the administrator use to continuously monitor and report on public access?
⚠ Common exam trap
Candidates often confuse 'detecting public access' with 'auditing access logs' (S3 server access logs) or 'threat detection' (GuardDuty), but the question specifically asks for continuous monitoring and reporting of the bucket's configuration state, which is exactly what AWS Config's managed rules provide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config provides a managed rule called 's3-bucket-public-read-prohibited' and 's3-bucket-public-write-prohibited' that continuously evaluates S3 bucket policies and ACLs against the desired configuration. When a bucket becomes publicly accessible, AWS Config flags it as noncompliant and can trigger automated remediation or notifications. This makes it the correct service for ongoing monitoring and reporting of public access to sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config
Why this is correct
AWS Config is correct because it provides continuous, real-time compliance evaluation of S3 bucket policies using managed rules such as s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited. It captures configuration changes via AWS Config recording and triggers rule evaluation both periodically and on configuration changes, alerting via SNS or auto-remediating through Systems Manager. This directly meets the requirement to evaluate bucket policies against public-access rules continuously.
- ✗
S3 server access logs
Why it's wrong here
S3 server access logs are not suitable because they are raw object-level request logs generated on a best-effort basis; they show who accessed the bucket, from which IP addresses, and what operations were performed, but they do not evaluate the bucket's public-access configuration and cannot proactively alert when a policy becomes publicly accessible. To extract any security signal, you would need a separate log-processing pipeline, and even then you'd be auditing past activity rather than actively monitoring the policy state. Thus, they fail to deliver continuous, rule-based compliance evaluation.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that consumes CloudTrail events, VPC flow logs, and DNS logs to identify suspicious activity such as anomalous API usage or potential credential compromise; it does not continuously assess the S3 bucket policy itself against a defined rule set. Although GuardDuty can occasionally generate a finding related to public access in certain attack scenarios, its purpose is threat detection, not configuration compliance, and it lacks the rule-driven evaluation pipeline that AWS Config provides for continuously verifying policy settings.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor does offer an S3 Bucket Permissions check that can flag buckets with open or public access, but that check refreshes on a periodic schedule (for example, every few hours for Business or Enterprise support plans) rather than running continuously. It provides a point-in-time snapshot of an issue at the last refresh, and it does not trigger rule evaluations, support custom rules, or respond to configuration changes in real time. Therefore, it cannot satisfy the requirement for continuous evaluation of bucket policies against specific public-access rules.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.