DOP-C02 exam dumps

DOP-C02 practice question 343 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 343

Single answer

An organization has implemented an AWS environment for running multiple critical applications. They must ensure that all S3 buckets comply with strict security controls, including enforcing encryption at rest and blocking public access. The organization also needs to monitor and automatically remediate non-compliant buckets. Which solution best meets these requirements?

  1. A

    Enable AWS Config with managed rules for S3 bucket compliance and use AWS Config Remediation to enforce encryption and block public access.

  2. B

    Create a Lambda function that periodically scans all S3 buckets, checks for compliance, and enforces encryption and public access restrictions.

  3. C

    Use AWS Trusted Advisor to identify non-compliant S3 buckets and manually remediate any issues.

  4. D

    Enable Server-Side Encryption with S3 default encryption and manually review bucket policies for public access restrictions.

Show answer and explanation

Correct answer: A

Explanation

AWS Config is designed to help monitor, evaluate, and enforce compliance across AWS resources, including S3 buckets. By enabling Config managed rules and remediation, organizations can automatically detect and remediate non-compliance with security controls such as encryption and public access restrictions. This ensures continuous compliance and reduces manual intervention.

  • A. Correct.

    This is the correct answer. AWS Config provides managed rules such as 's3-bucket-server-side-encryption-enabled' and 's3-bucket-public-read-prohibited' to detect non-compliant buckets. Config Remediation can automatically apply actions to enforce compliance, making it a scalable and automated solution.

  • B. Incorrect.

    While a Lambda function could be customized to achieve this, it would require significant development effort and maintenance, which is not ideal compared to the managed solution provided by AWS Config.

  • C. Incorrect.

    AWS Trusted Advisor can help identify some security issues, but it does not provide automated remediation or the ability to enforce encryption and public access restrictions.

  • D. Incorrect.

    Enabling S3 default encryption and manually reviewing bucket policies addresses part of the requirements but lacks automation and scalability. It also does not ensure continuous compliance monitoring.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam