Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Automated remediation Practice Question

A security team needs to implement automated remediation for non-compliant resources in a cloud environment. They want to automatically fix public object storage bucket policies. Which combination of services should be used?

⚠ Common exam trap

A common mix-up: candidates confuse detection services (GuardDuty, Security Hub) with remediation services; CCSP candidates must recognize that automated remediation requires both a compliance evaluation engine and an execution mechanism, not just monitoring or alerting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configuration management service and serverless compute function

Automated remediation of non-compliant resources requires a configuration management service to detect and evaluate compliance (e.g., AWS Config rules) and a serverless compute function (e.g., AWS Lambda) to execute the remediation action, such as modifying a public S3 bucket policy. This combination enables event-driven, automatic correction without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Audit logging service and serverless compute function

    Why it's wrong here

    Audit logging records API activity for later review; it detects nothing and cannot trigger remediation, so the bucket policy stays public. It is tempting because logging underpins compliance evidence, and it would be correct where the requirement is retrospective investigation or forensic traceability rather than automatic correction.

  • ✗

    Threat detection service and workflow orchestration service

    Why it's wrong here

    Threat detection identifies malicious or anomalous behaviour, not configuration drift, and workflow orchestration only sequences actions once something else raises the finding. It is tempting because orchestration is genuinely used to automate multi-step responses, but it would be correct when a detection service supplies the trigger.

  • ✗

    Security hub and vulnerability management service

    Why it's wrong here

    A security hub aggregates findings and vulnerability management scans workloads for software flaws; neither evaluates bucket policy configuration nor applies a corrective change. It is tempting because both surface compliance posture, and they would be correct where the goal is prioritised visibility of weaknesses rather than automatic remediation.

  • ✓

    Configuration management service and serverless compute function

    Why this is correct

    A configuration management service continuously evaluates resource configuration against policy and detects non-compliant public bucket policies, then invokes a serverless function to remediate them automatically. This pairing satisfies the requirement for automated, event-driven correction without manual intervention.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.