Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Cloud Security Operations Practice Question

A cloud security team wants to automatically remediate misconfigured S3 buckets that are publicly accessible. Which combination of AWS services can be used to detect and automatically fix this issue?

⚠ Common exam trap

CCSP often tests the difference between threat detection (GuardDuty), auditing (CloudTrail), and configuration compliance (Config), so candidates must match the service to the requirement of detecting and remediating misconfigurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config and AWS Lambda

AWS Config continuously monitors and records resource configurations, including S3 bucket policies and ACLs, and can evaluate them against desired rules. When a bucket is found to be publicly accessible, AWS Config can trigger an AWS Lambda function to automatically remediate the misconfiguration, such as by applying a restrictive bucket policy or blocking public access. This combination provides detection and automated remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS GuardDuty and AWS Lambda

    Why it's wrong here

    GuardDuty generates findings on suspicious activity but does not evaluate bucket ACLs or policies for public access, so it cannot detect this misconfiguration. It is tempting because GuardDuty and Lambda are both security-automation services, and the pairing would be correct for remediating compromised credentials or malicious network behaviour.

  • ✗

    AWS CloudTrail and AWS Lambda

    Why it's wrong here

    CloudTrail only logs API calls after they occur, and Lambda alone has no trigger evaluating bucket policy state. Detection requires AWS Config rules, which invoke Lambda for remediation. CloudTrail with Lambda would be correct for responding to recorded API events, not for continuously assessing resource configuration compliance.

  • ✓

    AWS Config and AWS Lambda

    Why this is correct

    AWS Config rules continuously evaluate bucket policies and ACLs, flagging public access as non-compliant. The configuration change then triggers a Lambda function that programmatically removes the public permissions, delivering automated detection and remediation without manual intervention.

  • ✗

    AWS Security Hub and AWS CloudTrail

    Why it's wrong here

    Security Hub aggregates and scores findings, while CloudTrail records API activity; neither evaluates bucket policies nor applies remediation. The correct pairing is AWS Config rules for detection and Lambda for automated correction. Security Hub and CloudTrail suit centralised visibility and audit trails, not automatic configuration fixes.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.