For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 03
    Medium1 markMultiple Choice
    Domain 1.2: Security ControlsSecurityOrganizationsAWS Config

    AWS SAP-C02 · Question 03 · Domain 1.2: Security Controls

    An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amazon S3 buckets across all accounts must block public access. If a bucket is created without this setting, it must be automatically remediated within minutes. Which solution meets these requirements with the LEAST operational overhead?

    Answer options:

    A.

    Deploy an AWS Lambda function in each account triggered by CloudTrail S3 events to modify bucket policies.

    B.

    Create an SCP in AWS Organizations to deny the s3:PutBucketPublicAccessBlock action if it attempts to allow public access. Use AWS Config rules with automated remediation to fix existing buckets.

    C.

    Use AWS Systems Manager Fleet Manager to run a script daily across all accounts to update S3 settings.

    D.

    Enable Amazon Macie in the management account to automatically block public access on all discovered buckets.

    How to approach this question

    Combine preventative controls (SCPs) with detective/responsive controls (Config).

    Full Answer

    B.Create an SCP in AWS Organizations to deny the s3:PutBucketPublicAccessBlock action if it attempts to allow public access. Use AWS Config rules with automated remediation to fix existing buckets.✓ Correct
    Service Control Policies (SCPs) provide central preventative guardrails. AWS Config with automated remediation provides near real-time detective and corrective capabilities.

    Common mistakes

    Relying solely on Lambda, which is hard to manage at scale.
    Question 02All questionsQuestion 04

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts a...HardQ02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...HardQ06A company is setting up a multi-account AWS environment using AWS Control Tower. They need to ens...Medium
    View all 75 questions →