Courseiva
Security and Compliance →easyMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company's security policy requires that all Amazon S3 buckets must have server-side encryption enabled. The SysOps administrator needs to automatically detect any bucket that does not have encryption enabled and notify the security team. Which AWS service should be used to detect non-compliant buckets?

⚠ Common exam trap

A common mix-up: candidates confuse AWS Config's configuration compliance monitoring with AWS CloudTrail's API logging or GuardDuty's threat detection, leading candidates to choose a service that records actions rather than one that evaluates resource states.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config is the correct service because it continuously monitors and evaluates the configuration of AWS resources against desired policies. By using an AWS Config managed rule such as `s3-bucket-server-side-encryption-enabled`, you can automatically detect any S3 bucket that lacks server-side encryption and trigger an SNS notification to the security team.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is an agent-based vulnerability management service that scans EC2 instances and container images for software vulnerabilities and network exposure, not S3 bucket configuration settings. It has no visibility into bucket policies, default encryption attributes, or object-level metadata. Consequently, Inspector cannot detect whether a bucket has S3 default encryption disabled, making it unsuitable for this compliance requirement.

  • ✓

    AWS Config

    Why this is correct

    AWS Config is the correct service because it provides managed rules such as s3-bucket-default-encryption-enabled and s3-bucket-encryption-enabled that continuously evaluate S3 bucket configurations. When a bucket is created or altered without default encryption, AWS Config records it as non-compliant and can trigger SNS notifications or Amazon EventBridge rules to alert security teams. It also maintains a complete configuration history and compliance timeline, making it ideal for automatically detecting and auditing encryption settings across all S3 buckets.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity in the management and data planes, including calls like CreateBucket or PutBucketEncryption, for security investigation and operational auditing. However, it does not proactively inspect resource configuration state or evaluate whether encryption is actually enabled on an S3 bucket. To use CloudTrail for this purpose, an administrator would need to write custom query logic against the logs, and even then it would not provide automatic, continuous compliance notifications. Therefore, CloudTrail is not the right tool for enforcing an all-buckets-must-have-encryption policy.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a managed threat detection service that analyzes CloudTrail events, VPC Flow Logs, and DNS logs using machine learning and anomaly detection to identify threats such as compromised credentials or data exfiltration. It does not inspect bucket-level configuration settings, including whether S3 default encryption is enabled. GuardDuty's focus is on detecting active malicious activity, not on compliance drift or configuration policy enforcement, so it cannot reliably identify unencrypted S3 buckets.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.