Courseiva
easyMultiple ChoiceObjective-mapped

CCSP Compliance rule Practice Question

Network Topology
$ aws configservice describe-compliance-by-config-ruleconfig-rule-names s3-bucket-ssl-requests-only"ComplianceByConfigRules": ["ConfigRuleName": "s3-bucket-ssl-requests-only","Compliance": "NON_COMPLIANT"

Refer to the exhibit. A company uses a cloud configuration management tool to evaluate compliance with a rule that requires cloud storage buckets to enforce SSL. What should the administrator do next?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Check which bucket is non-compliant [CORRECT]

The output shows the rule is non-compliant but does not identify which specific bucket(s). The logical next step is to check which resources are non-compliant. Enabling SSL-only access is a solution but first the administrator must identify the non-compliant bucket. Disabling the rule or updating it would not resolve the issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable SSL-only access on the bucket [wrong]

    Why it's wrong here

    The administrator does not know which bucket is non-compliant yet.

  • Disable the compliance rule [wrong]

    Why it's wrong here

    Disabling the rule would remove visibility into compliance.

  • Update the rule to allow HTTP [wrong]

    Why it's wrong here

    Updating the rule would lower the security standard.

  • Check which bucket is non-compliant [CORRECT]

    Why this is correct

    The administrator must identify the non-compliant resource before taking action.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.