A company uses AWS Organizations and deployed a landing zone with AWS Control Tower. The company needs governance so that Amazon RDS DB instances that are not encrypted at rest in the production OU are detected. Which solution satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable the appropriate guardrail from the AWS Control Tower list of strongly recommended guardrails. Apply that guardrail to the production OU..
Why this is the answer
The correct solution is to enable the appropriate guardrail from the AWS Control Tower list of strongly recommended guardrails and apply it to the production OU. AWS Control Tower offers a set of predefined guardrails, including those for detecting unencrypted Amazon RDS DB instances, which are categorized as strongly recommended. These guardrails are pre-built AWS Config rules and SCPs designed to enforce common security and compliance best practices. Enabling mandatory guardrails is incorrect because mandatory guardrails are always enabled and cannot be selectively applied or disabled. Creating a new mandatory guardrail with AWS Config is incorrect because mandatory guardrails are predefined by Control Tower and cannot be user-created. Creating a custom SCP is incorrect because while SCPs can prevent the creation of unencrypted resources, they cannot detect existing unencrypted resources, which is required by the problem statement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed