SAP-C02 exam dumps

SAP-C02 practice question 413 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 413

Single answer

A company wants to ensure compliance with its security policies by automatically remediating non-compliant resources in its AWS environment. The company uses AWS Config to evaluate the compliance status of resources. They want to automatically disable public access for any Amazon S3 bucket that becomes non-compliant with their configuration rule. Which solution should you implement to meet this requirement?

  1. A

    Use an AWS Config custom rule with an AWS Lambda function that disables public access for non-compliant S3 buckets.

  2. B

    Enable an AWS Config managed rule for S3 bucket policies and configure the rule to disable public access automatically.

  3. C

    Set up EventBridge rules to monitor AWS Config compliance change events and trigger an AWS Systems Manager Automation document to remediate non-compliant S3 buckets.

  4. D

    Use AWS Config to monitor compliance and manually review non-compliant resources using the AWS Management Console.

Show answer and explanation

Correct answer: A

Explanation

To implement automated remediation for non-compliant S3 buckets, you need to use an AWS Config custom rule with an AWS Lambda function. The Lambda function is triggered when a resource becomes non-compliant and can execute the necessary actions to remediate the issue, such as disabling public access on an S3 bucket. AWS Config managed rules cannot directly remediate resources, and while EventBridge and Systems Manager Automation could be used, they add complexity that is unnecessary in this case.

  • A. Correct.

    This is the correct solution. A custom AWS Config rule with an AWS Lambda function allows for automated remediation. The Lambda function can be triggered when a resource becomes non-compliant, and it can include logic to disable public access for the S3 bucket.

  • B. Incorrect.

    AWS Config managed rules can evaluate compliance but cannot perform automated remediation directly. You would need custom logic, such as a Lambda function, for this capability.

  • C. Incorrect.

    While EventBridge can monitor compliance change events, using Systems Manager Automation documents introduces unnecessary complexity compared to using AWS Config with a Lambda remediation function. This is not the most straightforward approach.

  • D. Incorrect.

    Manually reviewing resources does not meet the requirement for automated remediation. This option is not valid as it does not provide automation.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam