DOP-C02 exam dumps

DOP-C02 practice question 346 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 346

Single answer

Your organization is running a multi-account AWS environment managed through AWS Organizations. As part of ensuring security compliance with internal policies, you need to enforce specific controls to prevent users in all member accounts from disabling CloudTrail logs or modifying the configurations of AWS Config. Which solution should you implement to meet these requirements?

  1. A

    Create an SCP (Service Control Policy) at the root of your AWS Organization to deny actions related to CloudTrail and AWS Config modifications.

  2. B

    Configure a Lambda function in the management account to monitor changes to CloudTrail and AWS Config and revert unauthorized modifications.

  3. C

    Enable AWS Config recording in all member accounts and configure CloudWatch Alarms to alert when changes are made to CloudTrail or AWS Config.

  4. D

    Use IAM policies in all member accounts to restrict permissions to modify CloudTrail and AWS Config settings.

Show answer and explanation

Correct answer: A

Explanation

To enforce security compliance across all accounts in an AWS Organization, SCPs provide a preventive and organization-wide solution. By denying actions to disable CloudTrail or modify AWS Config at the organizational level, you ensure that even account administrators cannot bypass these controls. Other options, while useful for monitoring or reactive measures, do not provide the same level of comprehensive protection as SCPs.

  • A. Correct.

    This is the correct answer. Service Control Policies (SCPs) in AWS Organizations allow you to enforce deny policies across all member accounts. By creating an SCP that explicitly denies actions to disable CloudTrail or modify AWS Config, you ensure these controls cannot be overridden, even by account administrators.

  • B. Incorrect.

    While a Lambda function can monitor and revert changes, this approach is reactive rather than preventive. It also introduces additional complexity and does not guarantee immediate compliance in the event of unauthorized changes.

  • C. Incorrect.

    Enabling AWS Config recording and setting up CloudWatch Alarms is useful for monitoring, but it does not prevent unauthorized modifications to CloudTrail or AWS Config.

  • D. Incorrect.

    IAM policies are account-specific and cannot enforce organization-wide controls. SCPs are required to enforce restrictions across multiple accounts in an AWS Organization.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam