Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

An organization has a policy requiring that all Amazon EC2 instances launched in the production account must have detailed monitoring enabled for Amazon CloudWatch. A SysOps administrator needs to enforce this rule automatically. Which solution will ensure that any EC2 instance launched without detailed monitoring is automatically remediated?

⚠ Common exam trap

Many candidates choose Option C (CloudWatch Events + Lambda) because it seems reactive and automatic, but they overlook that CloudWatch Events may not reliably capture all RunInstances API calls (e.g., when instances are launched by Auto Scaling or other services) and that the Lambda function would need to handle race conditions and permissions, whereas AWS Config remediation is purpose-built for continuous compliance enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Config with the managed rule 'ec2-instance-detailed-monitoring-enabled' and configure an automatic remediation action using AWS Systems Manager Automation to enable detailed monitoring on non-compliant instances.

AWS Config with the managed rule 'ec2-instance-detailed-monitoring-enabled' continuously evaluates EC2 instances against the policy. When an instance is non-compliant (i.e., launched without detailed monitoring), the automatic remediation action uses an AWS Systems Manager Automation document to enable detailed monitoring on that instance, ensuring enforcement without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS Config with the managed rule 'ec2-instance-detailed-monitoring-enabled' and configure an automatic remediation action using AWS Systems Manager Automation to enable detailed monitoring on non-compliant instances.

    Why this is correct

    AWS Config's managed rule 'ec2-instance-detailed-monitoring-enabled' runs continuous evaluations against all recorded EC2 instances, marking any without detailed monitoring as non-compliant. Pairing this with an automatic remediation action leverages an AWS Systems Manager Automation document to run the 'ec2-monitor-instances' command or equivalent, enabling detailed monitoring without manual intervention. Because AWS Config already discovers and tracks instances, this solution covers both newly launched and pre-existing instances, requiring no custom code and providing a fully managed, auditable compliance enforcement loop.

  • ✗

    Use AWS Trusted Advisor to check for instances without detailed monitoring and send a notification to the administrator via email.

    Why it's wrong here

    AWS Trusted Advisor does offer checks for underutilized or improperly monitored resources, but its architecture is advisory only—it cannot perform changes on your behalf. At best, you could subscribe to email notifications or refresh the check periodically, but the administrator would still need to manually enable detailed monitoring on each flagged instance. This makes it a detection and alerting mechanism, not a policy enforcement mechanism, so it falls short of the requirement to enforce a policy that all instances have detailed monitoring.

  • ✗

    Use an Amazon CloudWatch Events rule to detect RunInstances API calls and trigger a Lambda function that enables detailed monitoring on newly launched instances.

    Why it's wrong here

    An Amazon CloudWatch Events rule (now Amazon EventBridge) that matches RunInstances API calls and invokes a Lambda function can enable detailed monitoring on new instances, but this approach has significant gaps. It requires you to write and maintain custom Lambda code, handle IAM permissions and potential race conditions, and it only addresses instances launched after the rule is deployed—existing non-compliant instances remain untouched. In contrast, AWS Config's managed rule with SSM Automation remediation immediately evaluates the entire current instance inventory and automatically fixes non-compliance with no custom development, making it operationally simpler and more complete.

  • ✗

    Use an IAM policy that denies the ec2:RunInstances action unless the user specifies the parameter to enable detailed monitoring.

    Why it's wrong here

    IAM policies cannot enforce a requirement that users pass the 'Monitoring' parameter with a value of 'true' when calling ec2:RunInstances, because no IAM condition key exists for that specific request parameter. Even if such a condition key existed, this approach would only affect new instance launches; it would do nothing for instances already running without detailed monitoring or for instances whose monitoring setting is changed after launch. Consequently, this option fails both as a preventive control and as a corrective control, whereas AWS Config can continuously detect and remediate any drift.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.