Medium1 markMultiple Choice
Domain 3.1: Operational ExcellenceOperational ExcellenceAWS ConfigSystems Manager

AWS SAP-C02 · Question 11 · Domain 3.1: Operational Excellence

A company wants to improve operational excellence by automatically remediating non-compliant AWS resources. For example, if an S3 bucket is created without public access block enabled, it should be automatically corrected. Which solution achieves this?

Answer options:

A.

Use AWS CloudTrail to trigger an AWS Lambda function that deletes the bucket.

B.

Use AWS Config rules to detect non-compliance and trigger AWS Systems Manager Automation documents for remediation.

C.

Use Amazon GuardDuty to detect the misconfiguration and block access via WAF.

D.

Use AWS Trusted Advisor to automatically apply the correct settings.

How to approach this question

Identify the service for configuration tracking (Config) and the service for automated operational tasks (Systems Manager).

Full Answer

B.Use AWS Config rules to detect non-compliance and trigger AWS Systems Manager Automation documents for remediation.✓ Correct
AWS Config continuously monitors resource configurations. When a resource violates a rule, Config can trigger an SSM Automation document to automatically fix the issue.

Common mistakes

Choosing CloudTrail + Lambda, which requires custom coding and maintenance.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 1

75 questions · hints · full answers · grading

More questions from this exam