A business must keep confidential financial records in Amazon S3 and its policy forbids any S3 bucket from being publicly readable or writable. A SysOps administrator needs a solution that automatically detects and removes S3 permissions that grant public read or write access, with minimal ongoing operational effort. Which AWS service should the administrator choose to accomplish this most efficiently?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS Config.
Why this is the answer
AWS Config is the most efficient solution because it continuously monitors and records resource configurations and can automatically evaluate recorded configurations against desired baselines using Config Rules. You can deploy a Config Rule specifically designed to detect and remediate public S3 bucket access, such as s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited, which can be configured to automatically revoke public permissions. AWS Security Hub aggregates security findings from various AWS services but doesn't natively provide automatic remediation for S3 permissions. AWS Trusted Advisor offers best practice checks but doesn't automatically enforce or remediate configurations. Amazon Inspector focuses on vulnerability management for EC2 instances and container images, not S3 bucket permissions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed