SOA-C02 Security and Compliance Practice Question
A SysOps administrator needs to ensure that all Amazon S3 buckets in an AWS account are encrypted at rest. The administrator wants to automatically remediate any bucket that is created without default encryption. Which AWS service should be used to achieve this with the least operational overhead?
⚠ Common exam trap
Watch out — candidates often assume AWS Config only provides detection and not remediation, overlooking the auto-remediation integration with Systems Manager Automation, or they may confuse AWS Config's managed rules with Trusted Advisor's advisory checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config with a managed rule and auto-remediation via AWS Systems Manager Automation
AWS Config with the managed rule 's3-bucket-default-encryption-enabled' can detect S3 buckets that lack default encryption. By attaching an AWS Systems Manager Automation document (e.g., 'AWS-EnableS3BucketEncryption') as an auto-remediation action, the administrator can automatically apply AES-256 or AWS-KMS encryption to noncompliant buckets without manual intervention, minimizing operational overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config with a managed rule and auto-remediation via AWS Systems Manager Automation
Why this is correct
AWS Config's managed rule `s3-bucket-default-encryption-enabled` continuously evaluates each bucket's configuration against the required encryption state. On detecting a noncompliant bucket, Config invokes an SSM Automation runbook (e.g., `AWS-ConfigureS3BucketEncryption`) that calls `PutBucketEncryption` to enable default AES-256 or AWS KMS encryption automatically. Because this combines policy evaluation with an enforcement action, it satisfies the SysOps administrator's requirement directly without requiring custom code.
- ✗
AWS CloudTrail with Amazon CloudWatch Events and AWS Lambda
Why it's wrong here
CloudTrail is purely an audit service; it records API calls such as `PutBucketEncryption` or `CreateBucket` to a log file, but it does not compare a bucket's actual settings to a desired policy. To remediate, you would need a custom Lambda function that ingests CloudWatch Events, filters for S3 events, checks the bucket's encryption state, and then calls the S3 API to apply encryption — an approach that requires writing and maintaining code for each possible event type. It also fails to catch pre-existing noncompliant buckets that do not generate new API activity.
- ✗
AWS Trusted Advisor with Amazon Simple Notification Service (SNS)
Why it's wrong here
AWS Trusted Advisor provides best-practice recommendations, including an S3 bucket permission check, but its checks are advisory and do not include a check for default encryption on buckets. Even when a Trusted Advisor alert is published to an SNS topic, it only generates a notification — there is no remediation step to call the S3 encryption API, so the bucket remains noncompliant. Thus, it offers visibility but no enforcement mechanism.
- ✗
Amazon Inspector with AWS Systems Manager Patch Manager
Why it's wrong here
Amazon Inspector is designed for EC2 instances, inspecting network reachability and host-level vulnerabilities like CVE exposures, and it has no visibility into S3 bucket encryption attributes. AWS Systems Manager Patch Manager is likewise focused on applying OS patches to managed instances, not on S3 resource configuration. Neither tool can evaluate or alter S3 bucket encryption, making this combination wholly ineffective for the stated requirement.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.