Courseiva
Security and Compliance →easyMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator needs to ensure that all Amazon S3 buckets in an AWS account are encrypted at rest. The administrator wants to automatically remediate any bucket that is created without default encryption. Which AWS service should be used to achieve this with the least operational overhead?

⚠ Common exam trap

Watch out — candidates often assume AWS Config only provides detection and not remediation, overlooking the auto-remediation integration with Systems Manager Automation, or they may confuse AWS Config's managed rules with Trusted Advisor's advisory checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config with a managed rule and auto-remediation via AWS Systems Manager Automation

AWS Config with the managed rule 's3-bucket-default-encryption-enabled' can detect S3 buckets that lack default encryption. By attaching an AWS Systems Manager Automation document (e.g., 'AWS-EnableS3BucketEncryption') as an auto-remediation action, the administrator can automatically apply AES-256 or AWS-KMS encryption to noncompliant buckets without manual intervention, minimizing operational overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Config with a managed rule and auto-remediation via AWS Systems Manager Automation

    Why this is correct

    AWS Config's managed rule `s3-bucket-default-encryption-enabled` continuously evaluates each bucket's configuration against the required encryption state. On detecting a noncompliant bucket, Config invokes an SSM Automation runbook (e.g., `AWS-ConfigureS3BucketEncryption`) that calls `PutBucketEncryption` to enable default AES-256 or AWS KMS encryption automatically. Because this combines policy evaluation with an enforcement action, it satisfies the SysOps administrator's requirement directly without requiring custom code.

  • ✗

    AWS CloudTrail with Amazon CloudWatch Events and AWS Lambda

    Why it's wrong here

    CloudTrail is purely an audit service; it records API calls such as `PutBucketEncryption` or `CreateBucket` to a log file, but it does not compare a bucket's actual settings to a desired policy. To remediate, you would need a custom Lambda function that ingests CloudWatch Events, filters for S3 events, checks the bucket's encryption state, and then calls the S3 API to apply encryption — an approach that requires writing and maintaining code for each possible event type. It also fails to catch pre-existing noncompliant buckets that do not generate new API activity.

  • ✗

    AWS Trusted Advisor with Amazon Simple Notification Service (SNS)

    Why it's wrong here

    AWS Trusted Advisor provides best-practice recommendations, including an S3 bucket permission check, but its checks are advisory and do not include a check for default encryption on buckets. Even when a Trusted Advisor alert is published to an SNS topic, it only generates a notification — there is no remediation step to call the S3 encryption API, so the bucket remains noncompliant. Thus, it offers visibility but no enforcement mechanism.

  • ✗

    Amazon Inspector with AWS Systems Manager Patch Manager

    Why it's wrong here

    Amazon Inspector is designed for EC2 instances, inspecting network reachability and host-level vulnerabilities like CVE exposures, and it has no visibility into S3 bucket encryption attributes. AWS Systems Manager Patch Manager is likewise focused on applying OS patches to managed instances, not on S3 resource configuration. Neither tool can evaluate or alter S3 bucket encryption, making this combination wholly ineffective for the stated requirement.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.