AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

A company wants to continuously verify that all Amazon S3 buckets in its account remain compliant with a rule requiring public access to be blocked, and automatically flag any bucket that becomes non-compliant. Which AWS service should they use?

  1. AAWS IAM Access Analyzer
  2. BAmazon Inspector
  3. CAWS CloudTrail
  4. DAWS Config
Show answer & explanation

Correct answer: D. AWS Config

AWS Config continuously monitors and records resource configurations and evaluates them against defined rules, automatically flagging resources like S3 buckets that drift into a non-compliant state, such as becoming publicly accessible.

Why the other options are wrong

  • A. IAM Access Analyzer identifies resources shared with external entities but is not a general configuration compliance engine.
  • B. Amazon Inspector assesses vulnerabilities in compute resources, not S3 bucket configuration compliance.
  • C. CloudTrail logs API activity but does not evaluate ongoing configuration compliance.

AWS Config

A service that continuously monitors and records AWS resource configurations and evaluates them against desired rules for compliance.

  • Uses Config Rules to check for compliance conditions
  • Provides configuration history and change timeline for resources
  • Can trigger automated remediation actions for non-compliant resources

Memory trick: Config keeps configs compliant continuously.

More Security and Compliance questions