A company has enabled server access logging for its S3 buckets and wants an automated way to detect and remediate any existing or newly created buckets that do not have access logging enabled. Which solution provides the most operationally efficient enforcement?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable automatic remediation in AWS Config using the managed rule s3-bucket-logging-enabled..
Why this is the answer
Enabling automatic remediation in AWS Config using the managed rule s3-bucket-logging-enabled is the most operationally efficient solution. AWS Config continuously monitors resource configurations against predefined rules. The s3-bucket-logging-enabled rule specifically checks if S3 bucket access logging is enabled. When integrated with automatic remediation, AWS Config can automatically apply the necessary configuration changes (enabling logging) to non-compliant buckets without manual intervention or custom code. Using CloudTrail and a Lambda function would require developing and maintaining custom code for detection and remediation. AWS Trusted Advisor provides recommendations but doesn't offer automatic remediation. CloudWatch metrics can monitor certain aspects but are not designed for direct configuration compliance and remediation like AWS Config.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed