SAP-C02 exam dumps

SAP-C02 practice question 410 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 410

Select 3

Your company requires that all Amazon S3 buckets must have server-side encryption enabled at all times. You need to ensure compliance by automatically detecting and remediating any S3 buckets that do not meet this requirement. Which combination of actions should you take to achieve this using AWS Config?

  1. A

    Create an AWS Config rule to check the 's3-bucket-server-side-encryption-enabled' compliance.

  2. B

    Set up an AWS Lambda function triggered by non-compliant findings, which enables server-side encryption for non-compliant S3 buckets.

  3. C

    Manually monitor the AWS Config dashboard for non-compliant buckets and enable server-side encryption.

  4. D

    Use Amazon CloudWatch Events to trigger a notification when AWS Config detects non-compliant resources.

  5. E

    Enable AWS Config's auto-remediation feature with a pre-built remediation action to enforce server-side encryption for S3 buckets.

Show answer and explanation

Correct answers: A, B, D

Explanation

To ensure automated monitoring and remediation of S3 buckets for server-side encryption compliance, you need to use AWS Config to detect non-compliant buckets, and then remediate them using AWS Lambda. Additionally, Amazon CloudWatch Events (EventBridge) can notify or trigger actions when AWS Config detects non-compliance. Manual monitoring is not automated, and AWS Config does not have a pre-built remediation action for this specific requirement.

  • A. Correct.

    This is correct because AWS Config provides a managed rule 's3-bucket-server-side-encryption-enabled' to check that all S3 buckets have server-side encryption enabled. This rule will automatically evaluate compliance.

  • B. Correct.

    This is correct because you can use an AWS Lambda function to automatically remediate non-compliant resources. The Lambda function can modify the bucket settings to enable server-side encryption.

  • C. Incorrect.

    This is incorrect because manual monitoring does not align with the requirement for automated remediation. AWS Config is designed to automate the detection and reporting of compliance issues.

  • D. Correct.

    This is correct because Amazon CloudWatch Events (now known as Amazon EventBridge) can be used to trigger notifications when AWS Config detects non-compliance. This is useful for alerting and triggering remediation actions.

  • E. Incorrect.

    This is incorrect because, while AWS Config supports auto-remediation, there is no pre-built remediation action specifically for enabling server-side encryption. Custom remediation using AWS Lambda is required.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam