A company uses AWS Config rules to identify Amazon S3 buckets that do not comply with the company’s data protection policy. The buckets are distributed across multiple AWS Regions and multiple AWS accounts within an AWS Organizations organization. The company needs a solution to remediate existing noncompliant buckets and any future noncompliant buckets. Which solution will meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy an AWS Config aggregator with organization-wide resource data aggregation. Create an AWS Lambda function that responds to AWS Config findings for noncompliant S3 buckets by deleting or reconfiguring the buckets..
Why this is the answer
The correct solution involves an AWS Config aggregator with organization-wide resource data aggregation to centralize compliance data across all accounts and Regions in AWS Organizations. An AWS Lambda function, triggered by AWS Config findings, can then automatically remediate noncompliant S3 buckets by deleting or reconfiguring them. This addresses both existing and future noncompliant buckets. Incorrect options: Using an SCP to prevent new noncompliant buckets is a proactive measure but does not remediate existing noncompliant buckets, which is a key requirement. Scoping the Config aggregator only to currently used accounts and Regions would miss noncompliant buckets in new accounts or Regions added to the organization, failing to address "future noncompliant buckets.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed