SOA-C02 Security and Compliance Practice Question
A company wants to ensure that its AWS resources are compliant with the CIS AWS Foundations Benchmark. Which TWO AWS services can be used to automate compliance checks and remediation?
⚠ Common exam trap
SOA-C02 often tests the confusion between detection services (GuardDuty, Inspector) and compliance services (Config, Security Hub) — candidates must match the service to the compliance use case.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config (option C) is correct because it continuously records resource configuration changes and evaluates them against managed or custom rules, including CIS AWS Foundations Benchmark conformance packs, and it supports automatic remediation through SSM Automation documents. AWS Security Hub (option D) is correct because it aggregates security findings and runs the CIS AWS Foundations Benchmark as a supported security standard, giving a compliance score and control-level findings that can drive automated response via EventBridge. AWS CloudTrail (option A) only logs API activity for auditing and does not perform compliance evaluation or remediation. Amazon Inspector (option B) is a vulnerability management service for EC2, ECR images, and Lambda, not a CIS benchmark compliance engine. Amazon GuardDuty (option E) is a threat detection service that identifies malicious or anomalous activity, not configuration compliance against the CIS benchmark.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail is an auditing service that records every API call made in your AWS account, producing a detailed event history of who made each request and when. However, it performs no evaluation of whether resource configurations are compliant with CIS benchmarks or internal policies, and it cannot trigger corrective actions. Compliance requires a service that actively compares resource state to rules, not one that merely logs past activity.
- ✗
Amazon Inspector
Why it's wrong here
Inspector is a vulnerability management service that automatically scans EC2 instances and container images for software vulnerabilities and unintentional network exposure through a network reachability assessment. It does not evaluate the configuration of broader AWS resources like S3 buckets, IAM policies, or security groups against CIS AWS Foundations Benchmark controls. Therefore, while Inspector is valuable for workload security, it cannot fulfill a resource-level compliance automation requirement.
- ✓
AWS Config
Why this is correct
AWS Config is the native service for tracking resource configuration changes and enforcing compliance through Config rules. You can deploy managed rules aligned with CIS benchmarks and, when a resource is found noncompliant, integrate remediation actions using SSM Automation documents or Lambda functions to automatically correct the drift. Config maintains a configuration item history for every resource, giving auditors the evidence needed to prove compliance over time, which makes it the core service for this use case.
- ✓
AWS Security Hub
Why this is correct
Security Hub is a valid choice because it continuously runs automated compliance checks against established standards such as the CIS AWS Foundations Benchmark across your entire AWS account. It aggregates findings from integrated AWS services like GuardDuty and Inspector into one dashboard, allowing you to track compliance status and prioritize noncompliant resources. While Security Hub does not automatically fix issues, it provides the required compliance verification and can trigger custom workflows through CloudWatch Events or EventBridge.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty is an intelligent threat detection service that consumes real-time feeds and machine learning to identify malicious activity like cryptocurrency mining, credential compromise, or port scanning within your account. It generates security findings for unusual behavior but does not assess the configuration of AWS resources against CIS benchmark controls, nor does it have any concept of compliance rules or remediation. Thus, it is not a tool for ensuring that resources are compliant with a chosen framework.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.