SOA-C02 Security and Compliance Practice Question
A company wants to enforce that all Amazon EC2 instances launched in the AWS account must have a specific termination protection setting enabled. The SysOps administrator needs to automatically remediate any instances that are launched without termination protection. Which AWS service should be used to achieve this?
⚠ Common exam trap
A common mix-up: candidates confuse AWS Config's managed rules (which cover common compliance checks) with the need for a custom rule and Lambda function to enforce a specific setting like termination protection, or mistakenly think services like Inspector or Patch Manager can handle configuration enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config with a custom rule using AWS Lambda to evaluate and enable termination protection.
AWS Config can evaluate resources against desired configurations using managed or custom rules. A custom AWS Config rule can invoke a Lambda function to check if termination protection is enabled on EC2 instances and automatically enable it if missing, providing the required remediation. This approach directly addresses the requirement to enforce termination protection on all launched instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config with a managed rule ec2-instance-no-public-ip and an SSM Automation remediation.
Why it's wrong here
The ec2-instance-no-public-ip managed rule only evaluates whether an EC2 instance has been assigned a public IPv4 address; it does not inspect the disableApiTermination attribute that controls termination protection. Attaching an SSM Automation remediation to this rule cannot address the requirement because the underlying compliance check is unrelated to the desired setting, and there is no native Automation document that repurposes the rule's evaluation. Consequently, instances lacking termination protection would remain compliant and un-remediated.
- ✓
AWS Config with a custom rule using AWS Lambda to evaluate and enable termination protection.
Why this is correct
A custom AWS Config rule can use a Lambda function to check if an EC2 instance has termination protection enabled. If not, the function can call the EC2 API to enable it. This provides automatic remediation for non-compliant resources.
- ✗
Amazon Inspector to scan instances and trigger a remediation action.
Why it's wrong here
Amazon Inspector is a vulnerability management service that performs network reachability assessments and host-agent-based scans for CVEs and security exposures; it does not read EC2 control-plane attributes such as disableApiTermination, nor does it provide an action to modify them. Even if a finding triggered a Lambda function, Inspector's event model reports software vulnerabilities and network exposure, not configuration drift in instance-level API settings. Therefore, it cannot evaluate or enforce termination protection compliance.
- ✗
AWS Systems Manager Patch Manager to apply a policy for termination protection.
Why it's wrong here
Systems Manager Patch Manager creates patching baselines and schedules that install OS updates on managed instances via the SSM agent inside the guest operating system. Termination protection is a property of the EC2 resource in the AWS control plane, stored as the disableApiTermination attribute, which Patch Manager never queries or modifies. There is no policy construct in Patch Manager that can apply EC2-level protections, so the service is entirely outside the scope of this requirement.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.