Courseiva
Operations and Support →mediumMultiple Choice

CV0-004 Operations and Support Practice Question

A cloud operations team needs to ensure that all Amazon S3 buckets in their AWS account have server access logging enabled. They want to automatically detect and remediate any bucket that does not have logging enabled. Which combination of AWS services should they use?

⚠ Common exam trap

The trap here is assuming that security services like GuardDuty or Inspector can enforce configuration compliance, when AWS Config is the service designed for configuration evaluation and remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config rule with automatic remediation using AWS Systems Manager Automation

The need is to detect and remediate S3 buckets without server access logging. AWS Config provides managed rules that can check for this configuration. When a bucket is non-compliant, Config can automatically run an SSM Automation document to enable logging. This creates a continuous compliance loop with automatic remediation, which is the most direct and native solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty with S3 protection and AWS Lambda remediation

    Why it's wrong here

    GuardDuty S3 protection detects suspicious activity in S3, such as unusual data access patterns, but it does not check configuration compliance like logging status. It cannot detect whether server access logging is enabled. Using GuardDuty for this purpose would not identify non-compliant buckets and would not trigger remediation for missing logging.

  • ✗

    Amazon Inspector with S3 assessment and AWS Systems Manager Automation

    Why it's wrong here

    Amazon Inspector assesses applications for vulnerabilities and unintended network exposure, but it does not evaluate S3 bucket configuration settings like server access logging. It is focused on EC2 and container workloads. Using Inspector here would not detect the missing logging configuration and would not provide the required remediation.

  • ✗

    AWS CloudTrail with Amazon EventBridge and AWS Lambda to enable logging

    Why it's wrong here

    CloudTrail logs API calls but does not evaluate resource configurations. While EventBridge can react to CloudTrail events, there is no event that indicates a bucket lacks server access logging. This approach would not detect the non-compliant state and would not automatically remediate it. It is suited for auditing, not configuration compliance.

  • ✓

    AWS Config rule with automatic remediation using AWS Systems Manager Automation

    Why this is correct

    AWS Config can evaluate S3 bucket configurations against a rule that checks if server access logging is enabled. When a bucket is non-compliant, Config can trigger automatic remediation using an SSM Automation document that enables logging. This provides continuous compliance and automatic correction, meeting the requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.