Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company has an S3 bucket that stores sensitive data. A SysOps administrator needs to detect when objects in the bucket are publicly accessible. Which AWS service should the administrator use to continuously monitor and report on public access?

⚠ Common exam trap

Candidates often confuse 'detecting public access' with 'auditing access logs' (S3 server access logs) or 'threat detection' (GuardDuty), but the question specifically asks for continuous monitoring and reporting of the bucket's configuration state, which is exactly what AWS Config's managed rules provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config provides a managed rule called 's3-bucket-public-read-prohibited' and 's3-bucket-public-write-prohibited' that continuously evaluates S3 bucket policies and ACLs against the desired configuration. When a bucket becomes publicly accessible, AWS Config flags it as noncompliant and can trigger automated remediation or notifications. This makes it the correct service for ongoing monitoring and reporting of public access to sensitive data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Config

    Why this is correct

    AWS Config is correct because it provides continuous, real-time compliance evaluation of S3 bucket policies using managed rules such as s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited. It captures configuration changes via AWS Config recording and triggers rule evaluation both periodically and on configuration changes, alerting via SNS or auto-remediating through Systems Manager. This directly meets the requirement to evaluate bucket policies against public-access rules continuously.

  • ✗

    S3 server access logs

    Why it's wrong here

    S3 server access logs are not suitable because they are raw object-level request logs generated on a best-effort basis; they show who accessed the bucket, from which IP addresses, and what operations were performed, but they do not evaluate the bucket's public-access configuration and cannot proactively alert when a policy becomes publicly accessible. To extract any security signal, you would need a separate log-processing pipeline, and even then you'd be auditing past activity rather than actively monitoring the policy state. Thus, they fail to deliver continuous, rule-based compliance evaluation.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that consumes CloudTrail events, VPC flow logs, and DNS logs to identify suspicious activity such as anomalous API usage or potential credential compromise; it does not continuously assess the S3 bucket policy itself against a defined rule set. Although GuardDuty can occasionally generate a finding related to public access in certain attack scenarios, its purpose is threat detection, not configuration compliance, and it lacks the rule-driven evaluation pipeline that AWS Config provides for continuously verifying policy settings.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor does offer an S3 Bucket Permissions check that can flag buckets with open or public access, but that check refreshes on a periodic schedule (for example, every few hours for Business or Enterprise support plans) rather than running continuously. It provides a point-in-time snapshot of an issue at the last refresh, and it does not trigger rule evaluations, support custom rules, or respond to configuration changes in real time. Therefore, it cannot satisfy the requirement for continuous evaluation of bucket policies against specific public-access rules.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.