SOA-C02 Security and Compliance Practice Question
A company manages multiple AWS accounts under AWS Organizations. The security team requires that all Amazon S3 buckets in the organization must be encrypted using AWS KMS (SSE-KMS). The SysOps administrator needs to automatically detect any bucket that is not compliant and remediate it by enabling SSE-KMS. Which AWS feature or service should be used to implement this automated compliance enforcement?
⚠ Common exam trap
Many exam-takers confuse AWS Config's evaluation and remediation capabilities with CloudTrail's logging or Trusted Advisor's advisory-only checks, failing to recognize that only AWS Config provides native automated remediation through Systems Manager Automation documents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config with the s3-bucket-server-side-encryption-enabled managed rule and automatic remediation using an AWS Systems Manager Automation document.
AWS Config's `s3-bucket-server-side-encryption-enabled` managed rule can evaluate S3 buckets for encryption compliance. When a non-compliant bucket is detected, AWS Config can trigger automatic remediation via an AWS Systems Manager Automation document that applies SSE-KMS encryption to the bucket. This provides a fully automated, policy-driven enforcement mechanism without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config with the s3-bucket-server-side-encryption-enabled managed rule and automatic remediation using an AWS Systems Manager Automation document.
Why this is correct
The managed rule `s3-bucket-server-side-encryption-enabled` continuously evaluates every S3 bucket in an AWS Region against the requirement that default encryption is enabled. When a bucket is noncompliant, automatic remediation triggers an AWS Systems Manager Automation document, typically `AWS-EnableS3BucketEncryption`, to directly apply SSE-KMS to that bucket. Because Config re-evaluates the rule periodically and whenever bucket configuration changes, this approach corrects existing noncompliant buckets on deployment and continuously handles any future drift without manual intervention.
- ✗
AWS CloudTrail to log bucket creation events and trigger an AWS Lambda function that applies SSE-KMS.
Why it's wrong here
While CloudTrail does log `CreateBucket` API calls and could use those events to trigger a Lambda function, this approach is entirely event-driven and only captures buckets created after the solution is in place. Preexisting noncompliant buckets are never evaluated, and a later change that removes or disables encryption would not generate a CreateBucket event, so the Lambda would never fire again. This custom logic lacks the periodic re-evaluation, compliance history, and native remediation orchestration that AWS Config provides, making it a brittle, one-shot mitigation rather than a real compliance mechanism.
- ✗
Amazon Inspector to scan S3 buckets for encryption compliance and automatically apply SSE-KMS.
Why it's wrong here
Amazon Inspector is a vulnerability management service designed for compute workloads, such as EC2 instances, Amazon ECR container images, and Lambda functions—it checks for Common Vulnerabilities and Exposures (CVEs) and unintended network exposure. It has no awareness of S3 bucket encryption attributes and cannot evaluate or modify storage resource configuration. Even if it could inspect buckets, Inspector does not integrate with Systems Manager Automation documents for remediation, so it cannot automatically apply SSE-KMS or any other encryption fix.
- ✗
AWS Trusted Advisor to check S3 bucket encryption and send notifications but not auto-remediate.
Why it's wrong here
Trusted Advisor's S3 bucket encryption check (available to Business and Enterprise support customers) can identify buckets that lack default encryption and report their status through dashboards or CloudWatch Events notifications. However, Trusted Advisor is strictly an advisory tool—it never changes resource states, so it cannot enable SSE-KMS or perform any remediation action. A sysadmin would be forced to remediate each noncompliant bucket manually or build a separate automation workflow, making this option incompatible with the requirement of automatic and continuous enforcement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.