Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company requires that all S3 buckets be tagged with a 'CostCenter' tag. A SysOps administrator needs to enforce this and prevent creation of untagged buckets. Which approach should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a service control policy (SCP) that denies s3:CreateBucket unless the request includes the required tag

AWS Organizations SCPs can be used to deny actions that do not meet certain conditions, such as requiring specific tags. An SCP with a condition for 'aws:RequestTag' can enforce tagging at bucket creation. IAM policies can also enforce tagging for specific users, but SCPs apply to all accounts in the organization. AWS Config rules can detect non-compliant resources but cannot prevent creation. CloudTrail is for logging, not enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply a service control policy (SCP) that denies s3:CreateBucket unless the request includes the required tag

    Why this is correct

    An SCP applied at the organizational unit (OU) or root level can explicitly deny s3:CreateBucket when the request lacks a specific tag key (e.g., cost-center). Because SCPs act as a guardrail for all accounts under the OU, they cannot be overridden by individual account IAM policies, making them the most reliable preventive control. The SCP would use a Condition block with the StringNotEquals or StringLike operator on aws:RequestTag, ensuring that only properly tagged bucket creation requests succeed.

  • ✗

    Create an IAM policy that allows s3:CreateBucket only if the bucket has the tag, and attach it to all users

    Why it's wrong here

    An IAM policy with a condition requiring the tag (e.g., using aws:RequestTag) only restricts the permissions of the users or roles it is attached to; it does nothing to constrain other principals such as the root user, service roles, or cross-account roles. In fact, the account root user, by default, can perform any action unless explicitly denied by an SCP, so untagged buckets may still be created outside the IAM policy's scope. Even when attached to all IAM users, the policy would not cover resources accessed via temporary credentials from other IAM entities or AWS services, leaving enforcement gaps that an SCP would close.

  • ✗

    Enable AWS CloudTrail to log bucket creation and review logs daily

    Why it's wrong here

    While CloudTrail can record s3:CreateBucket events, including the request parameters that show whether the tag was present, it is purely a detective control. Daily review of logs introduces a significant lag between an untagged bucket's creation and any corrective action, and it does not prevent the violation from occurring in the first place. Relying on manual log analysis is error-prone and does not scale across an organization with high bucket creation velocity, making it an unsuitable mechanism for enforcing a mandatory tagging policy.

  • ✗

    Use an AWS Config rule to automatically delete untagged buckets

    Why it's wrong here

    An AWS Config managed rule like required-tags can detect untagged buckets, but it is not designed to automatically delete or modify them; deletion would require a custom remediation action, typically via an AWS Lambda function or Systems Manager automation. Automatically deleting an S3 bucket is inherently dangerous because it can irreversibly destroy data, especially if the bucket is not versioned or lacks proper backups, and there is a risk of accidental removal of a newly created but legitimate bucket. Config is a detective and compliance-audit tool, not a preventive one, and automatic deletion is not a recommended practice for enforcing tagging.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.