nerdexam
Amazon

SOA-C02 · Question #101

A SysOps administrator has Nocked public access to all company Amazon S3 buckets. The SysOps administrator wants to be notified when an S3 bucket becomes publicly readable in the future. What is the M

The correct answer is D. Enable the s3-bucket-public-read-prohibited managed rule in AWS Config.. https://aws.amazon.com/blogs/security/how-to-use-aws-config-to-monitor-for-and-respond-to- amazon-s3-buckets-allowing-public-access/

Submitted by khalil_dz· Mar 30, 2026Monitoring, Logging, and Remediation

Question

A SysOps administrator has Nocked public access to all company Amazon S3 buckets. The SysOps administrator wants to be notified when an S3 bucket becomes publicly readable in the future. What is the MOST operationally efficient way to meet this requirement?

Options

  • ACreate an AWS Lambda function that periodically checks the public access settings for each S3
  • BCreate a cron script that uses the S3 API to check the public access settings for each S3 bucket.
  • CEnable S3 Event notified tons for each S3 bucket.
  • DEnable the s3-bucket-public-read-prohibited managed rule in AWS Config.

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    8% (4)
  • D
    84% (42)

Explanation

https://aws.amazon.com/blogs/security/how-to-use-aws-config-to-monitor-for-and-respond-to- amazon-s3-buckets-allowing-public-access/

Topics

#AWS Config managed rules#S3 public access#compliance monitoring#automated detection

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice