SOA-C02 Security and Compliance Practice Question
A company needs to comply with PCI DSS requirements for its AWS environment. Which TWO services should the SysOps administrator use to automate compliance checks and generate reports? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
(AWS Config) is correct because AWS Config provides managed rules that evaluate resource configurations against compliance standards like PCI DSS, and can trigger auto-remediation or generate compliance reports via AWS Config conformance packs. Option E (AWS Audit Manager) is correct because it helps continuously audit your AWS usage, automate evidence collection, and generate compliance reports for PCI DSS. Option A (Amazon CloudWatch) is incorrect because it is focused on monitoring metrics and logs, not on compliance checks or automated reporting. Option C (AWS CloudTrail) is incorrect because it records API activity for auditing but does not perform compliance checks or generate compliance reports. Option D (AWS Trusted Advisor) is incorrect because it provides best-practice recommendations but does not automate compliance checks or generate detailed compliance reports required by PCI DSS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch
Why it's wrong here
Amazon CloudWatch is a monitoring and observability service for collecting metrics, logs, and setting alarms based on operational thresholds. While you could build custom scripts to detect some configuration drifts, CloudWatch does not natively assess Amazon EC2, IAM, or Amazon S3 configurations against PCI DSS controls, nor does it produce compliance reports. Its purpose is real-time operational monitoring, not compliance automation.
- ✓
AWS Config
Why this is correct
AWS Config continuously records the configuration state of supported AWS resources and evaluates those configurations against AWS-managed or custom rules. For PCI DSS, you can use the managed rule pack to check for requirements like encrypted storage, restricted security group rules, and MFA on root accounts, then view the overall compliance snapshot over time. It generates a compliance timeline and aligned findings, making it the core service for automated configuration compliance.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is an audit logging service that captures API activity and user actions in your account, providing a definitive history for security analysis and forensic investigation. However, it does not compare resource configurations to PCI DSS controls, nor does it evaluate whether settings drift from a compliant baseline. CloudTrail logs what happened and by whom, whereas AWS Config evaluates the resulting resource configuration against compliance rules.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor offers best practice recommendations across cost optimization, performance, security, fault tolerance, and service limits, but it does not provide a compliance framework or automate PCI DSS reporting. Its security checks are limited to categories like security group open ports, IAM key rotation, and MFA on root, and they are not mapped to PCI DSS requirement levels. Trusted Advisor is advisory, not an automated compliance evaluator for the full PCI DSS scope.
- ✓
AWS Audit Manager
Why this is correct
AWS Audit Manager automates the collection of evidence and generates audit-ready reports for frameworks such as PCI DSS, HIPAA, and GDPR. It continuously gathers user activity, configuration snapshots (often sourced from AWS Config), and security findings to map them to specific control requirements, reducing manual effort for compliance assessments. This makes Audit Manager a powerful companion for PCI DSS, though the question's intended answer here is AWS Config, which provides the underlying configuration evaluation.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 247-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.