DOP-C02 exam dumps

DOP-C02 practice question 321 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 321

Select 3

Your organization uses AWS Config to ensure compliance across multiple AWS accounts within an AWS Organization. The security team has created a custom AWS Config rule to check for public read access on S3 buckets. They have noticed that the rule is not being evaluated in several accounts. What steps should you take to troubleshoot and resolve this issue?

  1. A

    Ensure that AWS Config is enabled in all accounts within the AWS Organization.

  2. B

    Verify that the custom rule's Lambda function has the necessary permissions to assume its execution role.

  3. C

    Check if the custom rule is properly deployed in the AWS Config aggregator.

  4. D

    Confirm that the AWS Organization has enabled trusted access for AWS Config.

  5. E

    Verify that the S3 buckets in the affected accounts are tagged properly for rule evaluation.

Show answer and explanation

Correct answers: A, B, D

Explanation

To troubleshoot AWS Config rule evaluation issues across multiple accounts, ensure AWS Config is enabled in all accounts, confirm that the custom rule's Lambda function has the necessary permissions, and verify that trusted access for AWS Config is enabled within the AWS Organization. These steps address the most likely causes of the issue described in the scenario.

  • A. Correct.

    AWS Config must be enabled in each account where you want to evaluate compliance. If AWS Config is not enabled in an account, the rule cannot be evaluated.

  • B. Correct.

    Custom AWS Config rules rely on Lambda functions to perform evaluations. If the Lambda function lacks the necessary permissions to assume its execution role, evaluations may fail.

  • C. Incorrect.

    AWS Config aggregators are used for centralized compliance management, but they do not directly deploy or evaluate rules. This option is irrelevant to rule evaluation issues.

  • D. Correct.

    Trusted access for AWS Config must be enabled in the AWS Organization to allow AWS Config to be managed centrally across accounts. Without this, AWS Config might not function properly in member accounts.

  • E. Incorrect.

    S3 bucket tagging is not a requirement for AWS Config rules to evaluate public read access. This is unrelated to the issue described.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam