SOA-C02 Security and Compliance Practice Question
A company's security policy requires that all Amazon S3 buckets must be non-publicly accessible. The SysOps administrator needs to automatically detect any bucket that becomes publicly accessible and automatically remediate it by applying a bucket policy that blocks public access. The solution should use AWS managed services with minimal custom code. Which combination of services should be used?
⚠ Common exam trap
Many exam-takers choose AWS IAM Access Analyzer (Option A) because it detects public access, but they overlook that it lacks built-in automatic remediation, requiring additional services and custom code to achieve the full requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config with managed rule and automatic remediation via SSM Automation
AWS Config with a managed rule (e.g., s3-bucket-public-read-prohibited or s3-bucket-public-write-prohibited) can continuously evaluate S3 bucket configurations against the security policy. When a bucket becomes publicly accessible, AWS Config triggers an automatic remediation action using an SSM Automation document that applies a bucket policy to block public access, all without custom code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS IAM Access Analyzer with Amazon EventBridge
Why it's wrong here
IAM Access Analyzer uses zone-of-trust analysis to identify resources shared with external principals, generating findings when an S3 bucket allows public or cross-account access. While EventBridge can be used to react to these findings, there is no built-in mechanism for automatically applying a fix; you would need to author and manage a custom Lambda function to change the bucket policy or enable S3 Block Public Access. This makes it a detection-and-notification pattern, not a managed enforcement solution.
- ✓
AWS Config with managed rule and automatic remediation via SSM Automation
Why this is correct
AWS Config continuously evaluates S3 bucket configurations against a managed rule such as s3-bucket-public-read-prohibited or s3-bucket-public-write-prohibited. When a bucket becomes noncompliant, AWS Config can invoke an automatic remediation using a prebuilt Systems Manager Automation document, for example AWS-DisableS3BucketPublicReadWrite, which applies the necessary bucket policy or public access block settings. Because this is a fully managed integration between Config and SSM Automation, it satisfies the security policy without custom code.
- ✗
AWS CloudTrail and AWS Lambda
Why it's wrong here
CloudTrail records S3 API operations and can deliver event history to a service like Lambda, but it is not a compliance engine and has no awareness of whether a bucket actually violates a security policy. To use it for remediation, you would need to build a custom Lambda function that parses trail logs, determines which buckets are public, and then applies corrective actions—a complex, maintenance-heavy approach. The combination lacks the native evaluate-and-remediate lifecycle that managed services provide.
- ✗
AWS Trusted Advisor and Amazon SNS
Why it's wrong here
Trusted Advisor runs a legacy S3 bucket permissions check that reports whether a bucket is readable or writable by anyone, but it only surfaces this as a recommendation alongside your cost, performance, and fault tolerance checks. SNS can broadcast those findings to operators, yet it has no remediation capability whatsoever, so no automatic action can be taken to enforce the company's security policy. It is a monitoring alert pattern, not an automated guardrail.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Amazon S3 to store sensitive customer data. A SysOps administrator needs to ensure that any S3 bucket that is incorrectly configured to allow public read access is automatically remediated within five minutes. The administrator wants to use native AWS services with minimal custom code. Which solution should be used?
medium- ✓ A.Use AWS Config with the 's3-bucket-public-read-prohibited' managed rule and configure automatic remediation to block public access.
- B.Create an Amazon EventBridge (CloudWatch Events) rule that triggers an AWS Lambda function to check and fix public read access.
- C.Apply an S3 bucket policy to each bucket that denies public read access.
- D.Use AWS Trusted Advisor to check for public read access and manually remediate when notified.
Why A: AWS Config with the 's3-bucket-public-read-prohibited' managed rule can automatically evaluate S3 bucket configurations against the desired state. When a non-compliant bucket is detected, AWS Config can trigger an automatic remediation action (e.g., applying an S3 bucket policy or blocking public access) using AWS Systems Manager Automation documents, all within the required five-minute window and with minimal custom code.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.