SOA-C02 Monitoring, Logging, and Remediation Practice Question
A company uses AWS CloudFormation to deploy a stack that includes an EC2 instance and an S3 bucket. The SysOps administrator needs to monitor the stack for any changes to the S3 bucket's bucket policy. Which AWS service should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it can track changes to S3 bucket policies, evaluate them against desired configurations, and trigger notifications or remediation. AWS CloudTrail logs API calls that modify bucket policies but does not monitor the policy state itself. Amazon CloudWatch is used for monitoring metrics and logs, not for tracking configuration changes. AWS Trusted Advisor provides best practice recommendations and does not monitor bucket policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudWatch
Why it's wrong here
Amazon CloudWatch is a monitoring service for operational metrics and logs, not for auditing resource configuration. While you can create alarms based on S3 bucket metrics like BucketSizeBytes or invoke a custom event rule for API calls via CloudWatch Events, CloudWatch does not maintain a configuration history or evaluate whether the S3 bucket policy matches a desired state. Therefore, it cannot provide ongoing drift detection for a bucket policy after a CloudFormation deployment.
- ✓
AWS Config
Why this is correct
AWS Config continuously records configuration items for supported resources, including S3 bucket policies, and can evaluate those configurations against managed or custom rules. When someone manually changes the bucket policy, AWS Config detects the change, generates a configuration item, and can trigger a compliance notification through a rule such as s3-bucket-policy-grantee-check or a custom Lambda-backed rule. This makes it the correct service for detecting post-deployment drift from the intended policy.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is an audit service that logs API activity, such as PutBucketPolicy or DeleteBucketPolicy, showing who made a change and when. However, it does not inspect the current policy content or compare it to the template-defined policy, and it cannot tell you whether the policy is compliant at any given moment. Because it provides only a historical log of actions, not ongoing configuration evaluation, it is insufficient for continuous policy monitoring.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor performs best-practice checks across categories like security, cost optimization, and performance, and its S3 checks focus on publicly accessible buckets or open permissions. It does not maintain a baseline of the intended bucket policy from your CloudFormation template, nor does it track changes to the policy over time. Therefore, it cannot detect whether a manual modification deviates from the deployed configuration.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.