Courseiva
Security and ComplianceeasyMultiple SelectObjective-mapped

SOA-C02 Security and Compliance Practice Question

A company needs to comply with PCI DSS requirements for its AWS environment. Which TWO services should the SysOps administrator use to automate compliance checks and generate reports? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Config

(AWS Config) is correct because AWS Config provides managed rules that evaluate resource configurations against compliance standards like PCI DSS, and can trigger auto-remediation or generate compliance reports via AWS Config conformance packs. Option E (AWS Audit Manager) is correct because it helps continuously audit your AWS usage, automate evidence collection, and generate compliance reports for PCI DSS. Option A (Amazon CloudWatch) is incorrect because it is focused on monitoring metrics and logs, not on compliance checks or automated reporting. Option C (AWS CloudTrail) is incorrect because it records API activity for auditing but does not perform compliance checks or generate compliance reports. Option D (AWS Trusted Advisor) is incorrect because it provides best-practice recommendations but does not automate compliance checks or generate detailed compliance reports required by PCI DSS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Amazon CloudWatch

    Why it's wrong here

    Amazon CloudWatch is a monitoring and observability service for collecting metrics, logs, and setting alarms based on operational thresholds. While you could build custom scripts to detect some configuration drifts, CloudWatch does not natively assess Amazon EC2, IAM, or Amazon S3 configurations against PCI DSS controls, nor does it produce compliance reports. Its purpose is real-time operational monitoring, not compliance automation.

  • AWS Config

    Why this is correct

    AWS Config continuously records the configuration state of supported AWS resources and evaluates those configurations against AWS-managed or custom rules. For PCI DSS, you can use the managed rule pack to check for requirements like encrypted storage, restricted security group rules, and MFA on root accounts, then view the overall compliance snapshot over time. It generates a compliance timeline and aligned findings, making it the core service for automated configuration compliance.

  • AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is an audit logging service that captures API activity and user actions in your account, providing a definitive history for security analysis and forensic investigation. However, it does not compare resource configurations to PCI DSS controls, nor does it evaluate whether settings drift from a compliant baseline. CloudTrail logs what happened and by whom, whereas AWS Config evaluates the resulting resource configuration against compliance rules.

  • AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor offers best practice recommendations across cost optimization, performance, security, fault tolerance, and service limits, but it does not provide a compliance framework or automate PCI DSS reporting. Its security checks are limited to categories like security group open ports, IAM key rotation, and MFA on root, and they are not mapped to PCI DSS requirement levels. Trusted Advisor is advisory, not an automated compliance evaluator for the full PCI DSS scope.

  • AWS Audit Manager

    Why this is correct

    AWS Audit Manager automates the collection of evidence and generates audit-ready reports for frameworks such as PCI DSS, HIPAA, and GDPR. It continuously gathers user activity, configuration snapshots (often sourced from AWS Config), and security findings to map them to specific control requirements, reducing manual effort for compliance assessments. This makes Audit Manager a powerful companion for PCI DSS, though the question's intended answer here is AWS Config, which provides the underlying configuration evaluation.

About these practice questions

This SOA-C02 question is part of Courseiva's 247-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.