Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A company is migrating to AWS and needs to comply with SOC 2. Which cloud-native service would BEST help monitor and enforce security configurations across the AWS environment?

⚠ Common exam trap

CAS-005 often tests the confusion between CloudTrail (who did what — API activity) and AWS Config (what is the configuration state — compliance), since both are 'monitoring' services and candidates frequently swap them under time pressure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config is the service purpose-built for continuously assessing, auditing, and evaluating AWS resource configurations against desired baselines. It records configuration changes, evaluates them against Config Rules (including SOC 2-aligned conformance packs), and flags noncompliant resources. This directly maps to SOC 2's change management, monitoring, and configuration control criteria. CloudTrail, WAF, and Shield serve different purposes — API activity logging, web attack filtering, and DDoS mitigation respectively — none of which provide configuration compliance assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail records API activity for audit and forensics; it does not evaluate resource configurations against security rules or enforce them. CloudTrail is the right choice for tracking who called which API and when, whereas continuous configuration assessment and remediation require AWS Config and Security Hub.

  • ✗

    AWS WAF

    Why it's wrong here

    WAF filters inbound HTTP traffic against web exploit signatures at the edge; it neither inspects nor enforces the configuration state of AWS resources. WAF is correct for protecting public web applications from injection and similar attacks, not for SOC 2 configuration monitoring across the account.

  • ✓

    AWS Config

    Why this is correct

    AWS Config continuously records resource configurations and evaluates them against rules, flagging non-compliant changes across the account. This satisfies the SOC 2 monitoring and enforcement constraint by providing auditable configuration history and automated remediation triggers.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield provides DDoS protection at Layers 3 and 4, not configuration monitoring or compliance posture assessment. It is tempting because it is a native AWS security service, and it would be the right choice when defending an internet-facing workload against volumetric or application-layer DDoS attacks.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.