A company's network engineer builds and tests VPC network designs in a development account. The company must track changes to network resources, enforce strict compliance with network security policies, and retain historical network configurations. Which solution satisfies these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Record the current state of network resources by using AWS Config. Create rules that reflect the desired configuration settings. Set remediation for noncompliant resources..
Why this is the answer
The correct answer is to use AWS Config. AWS Config continuously monitors and records resource configurations, allowing you to track changes, audit configurations, and assess compliance against desired configurations using configurable rules. This directly addresses the requirements for tracking changes, enforcing security policies, and retaining historical configurations. The other options are less suitable: EventBridge and Lambda can detect changes but require significant custom development to build a comprehensive compliance and historical tracking solution comparable to AWS Config. CloudWatch Logs and custom metrics are primarily for operational monitoring and alerting, not for detailed resource configuration tracking and compliance enforcement. Systems Manager Inventory and State Manager are excellent for managing and enforcing configurations on EC2 instances and on-premises servers, but AWS Config is specifically designed for tracking and evaluating compliance of a broader range of AWS resources, including VPC components.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed