Medium1 markMultiple Choice
Domain 1.2: Security ControlsControl TowerSecurityS3

AWS SAP-C02 · Question 06 · Domain 1.2: Security Controls

An organization uses AWS Control Tower to manage its multi-account environment. They need to ensure that Amazon S3 Public Access is blocked across all accounts, and any non-compliant buckets are automatically remediated. Which combination of services provides the BEST solution?

Answer options:

A.

Deploy a custom AWS Lambda function in each account triggered by EventBridge to modify S3 bucket policies.

B.

Enable the AWS Control Tower strongly recommended guardrail for S3 Public Access block.

C.

Use AWS Systems Manager Patch Manager to run a script that blocks public access.

D.

Configure Amazon Macie to automatically delete public S3 buckets.

How to approach this question

Leverage native Control Tower features for multi-account governance.

Full Answer

B.Enable the AWS Control Tower strongly recommended guardrail for S3 Public Access block.✓ Correct
AWS Control Tower provides preventive and detective guardrails. The S3 Block Public Access guardrail is a standard feature that enforces this requirement organization-wide.

Common mistakes

Over-engineering with custom Lambda functions when a managed guardrail exists.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

75 questions · hints · full answers · grading

More questions from this exam