SAP-C02 exam dumps

SAP-C02 practice question 375 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 375

Select 2

A company has deployed a mission-critical application on AWS and wants to ensure that any unexpected changes to security group rules are quickly detected and automatically reverted to a predefined baseline. Additionally, the team wants to receive notifications whenever such changes occur. What is the most appropriate solution to achieve this?

  1. A

    Use AWS Config to track security group changes and configure an AWS Systems Manager Automation Document (SSM Document) to revert unauthorized changes.

  2. B

    Set up a CloudWatch alarm to monitor security group changes and invoke an AWS Lambda function to restore the baseline configuration.

  3. C

    Enable AWS Config with a custom remediation action to automatically restore security groups to the baseline and use Amazon SNS to send notifications.

  4. D

    Create an EventBridge rule to detect security group changes and invoke an AWS Lambda function to revert the changes and send notifications.

  5. E

    Use AWS Trusted Advisor to monitor security group configurations and enable automatic remediation for unauthorized changes.

Show answer and explanation

Correct answers: A, C

Explanation

To detect and automatically remediate security group changes, AWS Config is the most suitable service because it is designed to monitor configuration changes and enforce compliance with predefined rules. By pairing it with Systems Manager Automation Documents or custom remediation actions, the application can automatically revert unauthorized changes. Additionally, AWS Config integrates with Amazon SNS to send notifications. Other options, such as CloudWatch alarms and EventBridge, do not provide the same level of functionality and are less appropriate for this scenario.

  • A. Correct.

    Correct. AWS Config is designed to monitor and evaluate configuration changes for AWS resources. It can be paired with Systems Manager Automation Documents to automatically remediate unauthorized changes, making it a powerful solution for this use case.

  • B. Incorrect.

    Incorrect. While CloudWatch alarms can monitor metrics, they are not suitable for tracking configuration changes like security group modifications. AWS Config is more appropriate for this scenario.

  • C. Correct.

    Correct. AWS Config can assess compliance with a predefined baseline and use a custom remediation action to automatically restore resources to the desired state. It can also integrate with Amazon SNS for notifications.

  • D. Incorrect.

    Incorrect. While EventBridge can detect changes and trigger Lambda functions, it is not the most efficient or purpose-built solution for managing resource configurations and compliance. AWS Config is a more suitable service for this scenario.

  • E. Incorrect.

    Incorrect. AWS Trusted Advisor provides high-level recommendations but does not support automated monitoring, detection, or remediation of resource configuration changes like security groups.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam