SOA-C02 Security and Compliance Practice Question
A company requires that all S3 buckets be tagged with a 'CostCenter' tag. A SysOps administrator needs to enforce this and prevent creation of untagged buckets. Which approach should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a service control policy (SCP) that denies s3:CreateBucket unless the request includes the required tag
AWS Organizations SCPs can be used to deny actions that do not meet certain conditions, such as requiring specific tags. An SCP with a condition for 'aws:RequestTag' can enforce tagging at bucket creation. IAM policies can also enforce tagging for specific users, but SCPs apply to all accounts in the organization. AWS Config rules can detect non-compliant resources but cannot prevent creation. CloudTrail is for logging, not enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Apply a service control policy (SCP) that denies s3:CreateBucket unless the request includes the required tag
Why this is correct
An SCP applied at the organizational unit (OU) or root level can explicitly deny s3:CreateBucket when the request lacks a specific tag key (e.g., cost-center). Because SCPs act as a guardrail for all accounts under the OU, they cannot be overridden by individual account IAM policies, making them the most reliable preventive control. The SCP would use a Condition block with the StringNotEquals or StringLike operator on aws:RequestTag, ensuring that only properly tagged bucket creation requests succeed.
- ✗
Create an IAM policy that allows s3:CreateBucket only if the bucket has the tag, and attach it to all users
Why it's wrong here
An IAM policy with a condition requiring the tag (e.g., using aws:RequestTag) only restricts the permissions of the users or roles it is attached to; it does nothing to constrain other principals such as the root user, service roles, or cross-account roles. In fact, the account root user, by default, can perform any action unless explicitly denied by an SCP, so untagged buckets may still be created outside the IAM policy's scope. Even when attached to all IAM users, the policy would not cover resources accessed via temporary credentials from other IAM entities or AWS services, leaving enforcement gaps that an SCP would close.
- ✗
Enable AWS CloudTrail to log bucket creation and review logs daily
Why it's wrong here
While CloudTrail can record s3:CreateBucket events, including the request parameters that show whether the tag was present, it is purely a detective control. Daily review of logs introduces a significant lag between an untagged bucket's creation and any corrective action, and it does not prevent the violation from occurring in the first place. Relying on manual log analysis is error-prone and does not scale across an organization with high bucket creation velocity, making it an unsuitable mechanism for enforcing a mandatory tagging policy.
- ✗
Use an AWS Config rule to automatically delete untagged buckets
Why it's wrong here
An AWS Config managed rule like required-tags can detect untagged buckets, but it is not designed to automatically delete or modify them; deletion would require a custom remediation action, typically via an AWS Lambda function or Systems Manager automation. Automatically deleting an S3 bucket is inherently dangerous because it can irreversibly destroy data, especially if the bucket is not versioned or lacks proper backups, and there is a risk of accidental removal of a newly created but legitimate bucket. Config is a detective and compliance-audit tool, not a preventive one, and automatic deletion is not a recommended practice for enforcing tagging.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.