CAS-004 Security Architecture Practice Question
A company is migrating to AWS and needs to comply with SOC 2. Which cloud-native service would BEST help monitor and enforce security configurations across the AWS environment?
⚠ Common exam trap
CAS-005 often tests the confusion between CloudTrail (who did what — API activity) and AWS Config (what is the configuration state — compliance), since both are 'monitoring' services and candidates frequently swap them under time pressure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the service purpose-built for continuously assessing, auditing, and evaluating AWS resource configurations against desired baselines. It records configuration changes, evaluates them against Config Rules (including SOC 2-aligned conformance packs), and flags noncompliant resources. This directly maps to SOC 2's change management, monitoring, and configuration control criteria. CloudTrail, WAF, and Shield serve different purposes — API activity logging, web attack filtering, and DDoS mitigation respectively — none of which provide configuration compliance assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records API activity for audit and forensics; it does not evaluate resource configurations against security rules or enforce them. CloudTrail is the right choice for tracking who called which API and when, whereas continuous configuration assessment and remediation require AWS Config and Security Hub.
- ✗
AWS WAF
Why it's wrong here
WAF filters inbound HTTP traffic against web exploit signatures at the edge; it neither inspects nor enforces the configuration state of AWS resources. WAF is correct for protecting public web applications from injection and similar attacks, not for SOC 2 configuration monitoring across the account.
- ✓
AWS Config
Why this is correct
AWS Config continuously records resource configurations and evaluates them against rules, flagging non-compliant changes across the account. This satisfies the SOC 2 monitoring and enforcement constraint by providing auditable configuration history and automated remediation triggers.
- ✗
AWS Shield
Why it's wrong here
AWS Shield provides DDoS protection at Layers 3 and 4, not configuration monitoring or compliance posture assessment. It is tempting because it is a native AWS security service, and it would be the right choice when defending an internet-facing workload against volumetric or application-layer DDoS attacks.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.