DOP-C02 exam dumps

DOP-C02 practice question 320 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 320

Select 3

Your organization has recently adopted AWS Config to ensure compliance with regulatory policies. You are tasked with setting up AWS Config rules to monitor whether EC2 instances are using a specific security group and whether S3 buckets have public access blocked. Additionally, you need to ensure that any configuration changes are logged. Which combination of actions should you take to fulfill these requirements?

  1. A

    Create a custom AWS Config rule using an AWS Lambda function to check for the specific security group on EC2 instances.

  2. B

    Enable AWS Config managed rules such as 's3-bucket-public-read-prohibited' and 's3-bucket-public-write-prohibited' to monitor S3 bucket configurations.

  3. C

    Enable AWS CloudTrail to capture configuration changes and set up an Amazon S3 bucket to store the logs.

  4. D

    Use Amazon Inspector to scan EC2 instances for compliance with the required security group.

  5. E

    Enable AWS Config recording to track changes to resource configurations.

Show answer and explanation

Correct answers: A, B, E

Explanation

To fulfill the requirements, you need to use AWS Config's capabilities. Custom rules (via Lambda) can enforce specific conditions like EC2 instances using a designated security group. Managed rules simplify monitoring for common use cases like blocking public access to S3 buckets. Enabling AWS Config recording ensures that all resource configurations are tracked over time. AWS CloudTrail and Amazon Inspector, while valuable for other use cases, do not directly address the compliance monitoring required in this scenario.

  • A. Correct.

    Correct. AWS Config allows you to create custom rules using AWS Lambda functions for specific compliance checks, such as verifying that EC2 instances are using a specific security group.

  • B. Correct.

    Correct. AWS Config provides managed rules that can be easily enabled to check for common compliance requirements, such as ensuring S3 buckets do not allow public access.

  • C. Incorrect.

    Incorrect. While AWS CloudTrail logs API activity, it does not directly monitor or enforce compliance with resource configurations. AWS Config is used for this purpose.

  • D. Incorrect.

    Incorrect. Amazon Inspector is used for vulnerability management and security assessments, not for monitoring compliance with a specific security group or public access settings.

  • E. Correct.

    Correct. Enabling AWS Config recording is necessary to track and evaluate changes to resource configurations over time.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam