nerdexam
Amazon

SOA-C02 · Question #542

A company wants to store sensitive financial data within Amazon S3 buckets. The company has a corporate policy that does not allow public read or write access to the buckets. A SysOps administrator…

The correct answer is A. AWS Config. AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources. It can be used to monitor and detect changes to S3 bucket policies that may introduce public read or write access.

Submitted by ravi_2018· Mar 30, 2026Security and Compliance

Question

A company wants to store sensitive financial data within Amazon S3 buckets. The company has a corporate policy that does not allow public read or write access to the buckets. A SysOps administrator must create a solution to automatically remove S3 permissions that allow public read or write access. Which AWS service should the SysOps administrator use to meet these requirements in the MOST operationally efficient manner?

Options

  • AAWS Config
  • BAWS Security Hub
  • CAWS Trusted Advisor
  • DAmazon Inspector

How the community answered

(55 responses)
  • A
    73% (40)
  • B
    9% (5)
  • C
    15% (8)
  • D
    4% (2)

Explanation

AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources. It can be used to monitor and detect changes to S3 bucket policies that may introduce public read or write access.

Topics

#AWS Config#S3 public access#automated remediation#security compliance

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice