Skip to content
BytePatterns

SCS-C03 · Domain 6: Security Foundations and Governance · 14% of the exam

Task 6.3: Evaluate the compliance of AWS resources

Proving and keeping compliance: AWS Config rules, aggregators and remediation, Security Hub CSPM controls, evidence for auditors from AWS Artifact and AWS Config conformance packs (AWS Audit Manager, which the guide names, no longer accepts new customers), and reviews against best practice in the Well-Architected Tool.

Study it

  • Compliance checks: AWS Config rules, aggregators, remediation and Security Hub CSPM controls

    Lesson coming

  • Audit evidence: AWS Artifact, Config conformance packs and the Well-Architected Tool

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A security team wants S3 buckets that allow public read access to be fixed automatically within minutes in every account, and wants the team's channel notified each time a bucket becomes noncompliant. Which approach meets these requirements?

  1. AConfig rule auto-remediation via Automation, plus an EventBridge rule to SNS
  2. BA weekly review of the Trusted Advisor S3 bucket permissions check
  3. CAn AWS Config aggregator in the security account that collects all accounts
  4. DAmazon Macie automated sensitive data discovery across every account
Show the answer and why
  • AConfig rule auto-remediation via Automation, plus an EventBridge rule to SNS

    Correct

    Config remediation runs Automation documents on noncompliant resources, automatically if chosen, and Config compliance changes can be routed to targets through EventBridge.

  • BA weekly review of the Trusted Advisor S3 bucket permissions check

    Incorrect

    A weekly manual review neither fixes buckets within minutes nor sends a notification for each change.

  • CAn AWS Config aggregator in the security account that collects all accounts

    Incorrect

    An aggregator gives a read-only view of compliance data; it cannot change resources.

  • DAmazon Macie automated sensitive data discovery across every account

    Incorrect

    Macie looks for sensitive data and reports bucket access settings; it does not change bucket permissions.

Detection, remediation and notification are three separate parts: a Config rule, a remediation action, and an EventBridge rule on compliance changes.

Question 2 · choose 1

A company with 300 accounts in five Regions wants the CIS AWS Foundations Benchmark controls of Security Hub CSPM turned on in every account and Region, including accounts added later, and wants member accounts to be unable to turn them off. What should the security team do from the delegated Security Hub CSPM administrator account?

  1. ACross-Region aggregation with all five Regions linked to the home Region
  2. BCentral configuration with a policy that enables the standard for all accounts
  3. CAsk each account owner to enable the standard locally in every Region
  4. DAutomation rules that set the workflow status of CIS findings to NEW
Show the answer and why
  • ACross-Region aggregation with all five Regions linked to the home Region

    Incorrect

    Aggregation brings findings into the home Region; it does not enable standards in the member accounts.

  • BCentral configuration with a policy that enables the standard for all accounts

    Correct

    Configuration policies enable standards and controls for accounts and OUs across the home and linked Regions. Accounts set as centrally managed can be changed only by the delegated administrator.

  • CAsk each account owner to enable the standard locally in every Region

    Incorrect

    Local configuration is set separately in every account and Region and lets members change it.

  • DAutomation rules that set the workflow status of CIS findings to NEW

    Incorrect

    Automation rules change finding fields; they do not enable standards or controls.

Central configuration is the way to set standards and controls for a whole organization from one Region, and to keep members from changing them.

Question 3 · choose 2

An external auditor asks a company for two things: AWS's current SOC 2 report for the services the company uses, and a documented review of the company's workload against AWS best practices, with an improvement plan and recorded progress over time. Which AWS services should the company use? (Choose TWO.)

  1. AAWS Trusted Advisor
  2. BAWS Config conformance packs
  3. CAWS Artifact
  4. DSecurity Hub CSPM cross-Region aggregation
  5. EThe AWS Well-Architected Tool
Show the answer and why
  • AAWS Trusted Advisor

    Incorrect

    Trusted Advisor runs checks with recommendations. It provides neither AWS's audit reports nor a workload review with milestones.

  • BAWS Config conformance packs

    Incorrect

    Conformance packs evaluate resource configurations; they do not provide AWS's SOC reports or an architecture review.

  • CAWS Artifact

    Correct

    Artifact provides on-demand downloads of AWS security and compliance documents, such as SOC reports.

  • DSecurity Hub CSPM cross-Region aggregation

    Incorrect

    Aggregation consolidates findings; it is neither a compliance report from AWS nor a documented workload review.

  • EThe AWS Well-Architected Tool

    Correct

    A workload review in the tool produces an improvement plan, and milestones record the workload's state at points in time to show progress.

AWS's own compliance evidence comes from Artifact; evidence about your workload's design comes from Well-Architected reviews and milestones.

Question 4 · choose 1

A company new to Security Hub CSPM wants a standard developed by AWS that checks accounts and resources against AWS's own recommended security controls. Which standard should it turn on first?

  1. ACIS AWS Foundations Benchmark
  2. BAWS Foundational Security Best Practices
  3. CNIST SP 800-171
  4. DAWS Resource Tagging Standard
Show the answer and why
  • ACIS AWS Foundations Benchmark

    Incorrect

    The CIS benchmark is developed by the Center for Internet Security, not by AWS.

  • BAWS Foundational Security Best Practices

    Correct

    FSBP is developed by AWS and industry professionals as a set of controls for AWS security best practices.

  • CNIST SP 800-171

    Incorrect

    This standard protects controlled unclassified information.

  • DAWS Resource Tagging Standard

    Incorrect

    The tagging standard checks tags, not security best practices broadly.

Many organizations combine FSBP with a framework standard such as CIS for audits.

Question 5 · choose 1

A team wants AWS Config to report S3 buckets that allow public read access, with as little effort as possible. What should it use?

  1. AA custom Lambda rule written by the team
  2. BA CloudWatch alarm on S3 request metrics
  3. CAn AWS Config managed rule for this check
  4. DA CloudTrail trail that logs S3 data events
Show the answer and why
  • AA custom Lambda rule written by the team

    Incorrect

    Custom rules are for checks that no managed rule covers.

  • BA CloudWatch alarm on S3 request metrics

    Incorrect

    Request metrics show traffic, not whether a bucket is public.

  • CAn AWS Config managed rule for this check

    Correct

    AWS managed rules are predefined, customizable rules that Config uses to evaluate resources.

  • DA CloudTrail trail that logs S3 data events

    Incorrect

    Data events record requests; they do not evaluate configuration.

Start with managed rules and write custom rules only for company-specific checks.

Question 6 · choose 1

Auditors ask whether an account follows a common compliance framework, and the team wants a ready-made set of AWS Config rules mapped to it. What should the team start from?

  1. AAn empty conformance pack with one custom rule
  2. BA Config aggregator in the account
  3. CA conformance pack sample template
  4. DA remediation runbook for each resource type
Show the answer and why
  • AAn empty conformance pack with one custom rule

    Incorrect

    That leaves the team to build every rule mapping itself.

  • BA Config aggregator in the account

    Incorrect

    Aggregators combine data; they do not provide rule sets.

  • CA conformance pack sample template

    Correct

    AWS Config provides conformance pack sample templates, such as Operational Best Practices packs, that group rules for a framework.

  • DA remediation runbook for each resource type

    Incorrect

    Remediation fixes resources; it is not a framework rule set.

Sample templates are a starting point; review each rule against the auditor's actual requirements.

Question 7 · choose 1

A small company without other security tooling wants a quick list of checks such as exposed access keys, the IAM password policy and S3 bucket permissions. Which AWS service offers these security checks?

  1. AAWS Trusted Advisor
  2. BAWS Artifact
  3. CAWS Cost Explorer
  4. DAmazon CloudWatch Logs Insights
Show the answer and why
  • AAWS Trusted Advisor

    Correct

    Trusted Advisor's security category includes checks such as Exposed Access Keys, IAM Password Policy and S3 Bucket Permissions.

  • BAWS Artifact

    Incorrect

    Artifact provides AWS compliance reports and agreements.

  • CAWS Cost Explorer

    Incorrect

    Cost Explorer analyzes costs and usage.

  • DAmazon CloudWatch Logs Insights

    Incorrect

    Logs Insights queries logs; it has no built-in security checks.

Trusted Advisor is a good start; Security Hub CSPM gives broader, continuous control checks.

Question 8 · choose 1

A team fixed several failed controls this morning, but the Security Hub CSPM security score has not changed. The controls now show as passed. What explains this?

  1. AScores count only critical-severity controls
  2. BScores require AWS Business Support to refresh
  3. CScores refresh only when standards are re-enabled
  4. DSecurity scores are updated every 24 hours
Show the answer and why
  • AScores count only critical-severity controls

    Incorrect

    Scores are based on controls across the enabled standards.

  • BScores require AWS Business Support to refresh

    Incorrect

    Support plans do not affect score updates.

  • CScores refresh only when standards are re-enabled

    Incorrect

    Scores update on a schedule; standards need not be re-enabled.

  • DSecurity scores are updated every 24 hours

    Correct

    After first-time generation, Security Hub CSPM updates security scores every 24 hours and shows when a score was updated.

The summary score is the average of the scores of the enabled standards.

Practise domain 6 →Practise all domains →