Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company wants to enforce that all Amazon EC2 instances launched in the AWS account must have a specific termination protection setting enabled. The SysOps administrator needs to automatically remediate any instances that are launched without termination protection. Which AWS service should be used to achieve this?

⚠ Common exam trap

A common mix-up: candidates confuse AWS Config's managed rules (which cover common compliance checks) with the need for a custom rule and Lambda function to enforce a specific setting like termination protection, or mistakenly think services like Inspector or Patch Manager can handle configuration enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config with a custom rule using AWS Lambda to evaluate and enable termination protection.

AWS Config can evaluate resources against desired configurations using managed or custom rules. A custom AWS Config rule can invoke a Lambda function to check if termination protection is enabled on EC2 instances and automatically enable it if missing, providing the required remediation. This approach directly addresses the requirement to enforce termination protection on all launched instances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config with a managed rule ec2-instance-no-public-ip and an SSM Automation remediation.

    Why it's wrong here

    The ec2-instance-no-public-ip managed rule only evaluates whether an EC2 instance has been assigned a public IPv4 address; it does not inspect the disableApiTermination attribute that controls termination protection. Attaching an SSM Automation remediation to this rule cannot address the requirement because the underlying compliance check is unrelated to the desired setting, and there is no native Automation document that repurposes the rule's evaluation. Consequently, instances lacking termination protection would remain compliant and un-remediated.

  • ✓

    AWS Config with a custom rule using AWS Lambda to evaluate and enable termination protection.

    Why this is correct

    A custom AWS Config rule can use a Lambda function to check if an EC2 instance has termination protection enabled. If not, the function can call the EC2 API to enable it. This provides automatic remediation for non-compliant resources.

  • ✗

    Amazon Inspector to scan instances and trigger a remediation action.

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that performs network reachability assessments and host-agent-based scans for CVEs and security exposures; it does not read EC2 control-plane attributes such as disableApiTermination, nor does it provide an action to modify them. Even if a finding triggered a Lambda function, Inspector's event model reports software vulnerabilities and network exposure, not configuration drift in instance-level API settings. Therefore, it cannot evaluate or enforce termination protection compliance.

  • ✗

    AWS Systems Manager Patch Manager to apply a policy for termination protection.

    Why it's wrong here

    Systems Manager Patch Manager creates patching baselines and schedules that install OS updates on managed instances via the SSM agent inside the guest operating system. Termination protection is a property of the EC2 resource in the AWS control plane, stored as the disableApiTermination attribute, which Patch Manager never queries or modifies. There is no policy construct in Patch Manager that can apply EC2-level protections, so the service is entirely outside the scope of this requirement.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.