CCSP Cloud Security Operations Practice Question
A cloud security team wants to automatically remediate misconfigured S3 buckets that are publicly accessible. Which combination of AWS services can be used to detect and automatically fix this issue?
⚠ Common exam trap
CCSP often tests the difference between threat detection (GuardDuty), auditing (CloudTrail), and configuration compliance (Config), so candidates must match the service to the requirement of detecting and remediating misconfigurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config and AWS Lambda
AWS Config continuously monitors and records resource configurations, including S3 bucket policies and ACLs, and can evaluate them against desired rules. When a bucket is found to be publicly accessible, AWS Config can trigger an AWS Lambda function to automatically remediate the misconfiguration, such as by applying a restrictive bucket policy or blocking public access. This combination provides detection and automated remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS GuardDuty and AWS Lambda
Why it's wrong here
GuardDuty generates findings on suspicious activity but does not evaluate bucket ACLs or policies for public access, so it cannot detect this misconfiguration. It is tempting because GuardDuty and Lambda are both security-automation services, and the pairing would be correct for remediating compromised credentials or malicious network behaviour.
- ✗
AWS CloudTrail and AWS Lambda
Why it's wrong here
CloudTrail only logs API calls after they occur, and Lambda alone has no trigger evaluating bucket policy state. Detection requires AWS Config rules, which invoke Lambda for remediation. CloudTrail with Lambda would be correct for responding to recorded API events, not for continuously assessing resource configuration compliance.
- ✓
AWS Config and AWS Lambda
Why this is correct
AWS Config rules continuously evaluate bucket policies and ACLs, flagging public access as non-compliant. The configuration change then triggers a Lambda function that programmatically removes the public permissions, delivering automated detection and remediation without manual intervention.
- ✗
AWS Security Hub and AWS CloudTrail
Why it's wrong here
Security Hub aggregates and scores findings, while CloudTrail records API activity; neither evaluates bucket policies nor applies remediation. The correct pairing is AWS Config rules for detection and Lambda for automated correction. Security Hub and CloudTrail suit centralised visibility and audit trails, not automatic configuration fixes.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.