AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

Your company enabled the managed AWS Config rule s3-bucket-public-read-prohibited. The security team mandates that any noncompliant Amazon S3 bucket automatically blocks all public access within five minutes, and that AWS Config records the remediation. Which solution satisfies these requirements by using only native AWS Config capabilities?

  • Add the rule to an aggregator, deploy a conformance pack, and rely on pack-level remediation to block public access.

  • Configure the rule to trigger a Lambda function that removes public ACLs and enable a high-frequency evaluation schedule.

  • Attach an SSM Automation runbook to the rule and specify the remediation action to invoke AWSConfigRemediation-ConfigureS3BucketPublicAccessBlock using an IAM service role.

  • Set the rule's ComplianceType to AUTO_REMEDIATE and use an EventBridge rule to call the S3 PutPublicAccessBlock API.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot