SOA-C02 Security and Compliance Practice Question
A company's security policy requires that all Amazon S3 buckets must have server-side encryption enabled. The SysOps administrator needs to automatically detect any bucket that does not have encryption enabled and notify the security team. Which AWS service should be used to detect non-compliant buckets?
⚠ Common exam trap
A common mix-up: candidates confuse AWS Config's configuration compliance monitoring with AWS CloudTrail's API logging or GuardDuty's threat detection, leading candidates to choose a service that records actions rather than one that evaluates resource states.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it continuously monitors and evaluates the configuration of AWS resources against desired policies. By using an AWS Config managed rule such as `s3-bucket-server-side-encryption-enabled`, you can automatically detect any S3 bucket that lacks server-side encryption and trigger an SNS notification to the security team.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is an agent-based vulnerability management service that scans EC2 instances and container images for software vulnerabilities and network exposure, not S3 bucket configuration settings. It has no visibility into bucket policies, default encryption attributes, or object-level metadata. Consequently, Inspector cannot detect whether a bucket has S3 default encryption disabled, making it unsuitable for this compliance requirement.
- ✓
AWS Config
Why this is correct
AWS Config is the correct service because it provides managed rules such as s3-bucket-default-encryption-enabled and s3-bucket-encryption-enabled that continuously evaluate S3 bucket configurations. When a bucket is created or altered without default encryption, AWS Config records it as non-compliant and can trigger SNS notifications or Amazon EventBridge rules to alert security teams. It also maintains a complete configuration history and compliance timeline, making it ideal for automatically detecting and auditing encryption settings across all S3 buckets.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API activity in the management and data planes, including calls like CreateBucket or PutBucketEncryption, for security investigation and operational auditing. However, it does not proactively inspect resource configuration state or evaluate whether encryption is actually enabled on an S3 bucket. To use CloudTrail for this purpose, an administrator would need to write custom query logic against the logs, and even then it would not provide automatic, continuous compliance notifications. Therefore, CloudTrail is not the right tool for enforcing an all-buckets-must-have-encryption policy.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a managed threat detection service that analyzes CloudTrail events, VPC Flow Logs, and DNS logs using machine learning and anomaly detection to identify threats such as compromised credentials or data exfiltration. It does not inspect bucket-level configuration settings, including whether S3 default encryption is enabled. GuardDuty's focus is on detecting active malicious activity, not on compliance drift or configuration policy enforcement, so it cannot reliably identify unencrypted S3 buckets.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.