CCSP Automated remediation Practice Question
A security team needs to implement automated remediation for non-compliant resources in a cloud environment. They want to automatically fix public object storage bucket policies. Which combination of services should be used?
⚠ Common exam trap
A common mix-up: candidates confuse detection services (GuardDuty, Security Hub) with remediation services; CCSP candidates must recognize that automated remediation requires both a compliance evaluation engine and an execution mechanism, not just monitoring or alerting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuration management service and serverless compute function
Automated remediation of non-compliant resources requires a configuration management service to detect and evaluate compliance (e.g., AWS Config rules) and a serverless compute function (e.g., AWS Lambda) to execute the remediation action, such as modifying a public S3 bucket policy. This combination enables event-driven, automatic correction without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Audit logging service and serverless compute function
Why it's wrong here
Audit logging records API activity for later review; it detects nothing and cannot trigger remediation, so the bucket policy stays public. It is tempting because logging underpins compliance evidence, and it would be correct where the requirement is retrospective investigation or forensic traceability rather than automatic correction.
- ✗
Threat detection service and workflow orchestration service
Why it's wrong here
Threat detection identifies malicious or anomalous behaviour, not configuration drift, and workflow orchestration only sequences actions once something else raises the finding. It is tempting because orchestration is genuinely used to automate multi-step responses, but it would be correct when a detection service supplies the trigger.
- ✗
Security hub and vulnerability management service
Why it's wrong here
A security hub aggregates findings and vulnerability management scans workloads for software flaws; neither evaluates bucket policy configuration nor applies a corrective change. It is tempting because both surface compliance posture, and they would be correct where the goal is prioritised visibility of weaknesses rather than automatic remediation.
- ✓
Configuration management service and serverless compute function
Why this is correct
A configuration management service continuously evaluates resource configuration against policy and detects non-compliant public bucket policies, then invokes a serverless function to remediate them automatically. This pairing satisfies the requirement for automated, event-driven correction without manual intervention.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.