A company manages its infrastructure in a single AWS account. Three engineers administer and develop in that account. Occasionally, one engineer modifies another engineer's EC2 security group and introduces noncompliant security settings. A solutions architect must implement a system that records changes made by engineers and sends alerts when EC2 security group settings become noncompliant. What is the FASTEST way to achieve this?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable AWS Config for EC2 security groups to detect and record noncompliant changes, and send notifications of those changes through an Amazon Simple Notification Service (Amazon SNS) topic..
Why this is the answer
AWS Config is the fastest way to achieve this because it continuously monitors and records AWS resource configurations, including EC2 security groups, and can evaluate them against desired configurations (rules). When a security group becomes noncompliant, Config can trigger an Amazon SNS topic to send immediate alerts. This directly addresses the need to record changes and alert on noncompliance. Enabling CloudTrail and CloudWatch Events would record changes but requires custom logic to define and detect "noncompliant" settings, making it slower to implement than Config's built-in compliance checks. AWS Organizations and SCPs are for managing multiple accounts and preventing actions, not for detecting and alerting on noncompliant configurations within a single account after they occur. SCPs alone do not provide alerts for noncompliant settings.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed