SOA-C02 exam dumps

SOA-C02 practice question 46 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 46

Select 3

Your organization has implemented an AWS Config rule to ensure that all Amazon S3 buckets are encrypted with AWS Key Management Service (AWS KMS) keys. Upon violations, your team needs to automatically remediate the issue by enabling encryption on non-compliant S3 buckets. Which of the following steps would you take to implement this solution using AWS Systems Manager Automation runbooks?

  1. A

    Create a custom AWS Config rule that invokes an AWS Systems Manager Automation runbook to remediate non-compliant S3 buckets.

  2. B

    Use the managed AWS Config rule 's3-bucket-server-side-encryption-enabled' and associate it with an AWS Systems Manager Automation document for remediation.

  3. C

    Create an IAM role with permissions for AWS Systems Manager to modify S3 bucket policies and associate it with the Automation document.

  4. D

    Manually run the AWS Systems Manager Automation runbook whenever a non-compliant resource is detected by the AWS Config rule.

  5. E

    Enable auto-remediation in AWS Config to invoke the Systems Manager Automation document when a rule violation is detected.

Show answer and explanation

Correct answers: B, C, E

Explanation

To implement automatic remediation for non-compliant S3 buckets, you can use the AWS Config managed rule 's3-bucket-server-side-encryption-enabled' to detect violations. You then associate an AWS Systems Manager Automation document to take corrective action, such as enabling encryption on the bucket. Additionally, you must configure an IAM role with the required permissions for the Automation document and enable auto-remediation in AWS Config to trigger the automation automatically when a rule violation is detected.

  • A. Incorrect.

    This is incorrect because there is no need to create a custom AWS Config rule when a managed rule like 's3-bucket-server-side-encryption-enabled' already exists for this use case.

  • B. Correct.

    This is correct because the managed AWS Config rule 's3-bucket-server-side-encryption-enabled' checks for encryption compliance, and you can associate an AWS Systems Manager Automation document to remediate violations.

  • C. Correct.

    This is correct because AWS Systems Manager requires an IAM role with appropriate permissions to modify S3 bucket configurations during automation execution.

  • D. Incorrect.

    This is incorrect because manually running the Automation runbook does not align with the requirement for automatic remediation.

  • E. Correct.

    This is correct because enabling auto-remediation in AWS Config ensures that the Systems Manager Automation document is invoked automatically upon rule violations.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam