A development team creates new S3 buckets daily. The security team requires that all current and future buckets have encryption, logging, and versioning enabled, and that no bucket is ever publicly readable or writable. What should a DevOps engineer implement to ensure compliance?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable AWS Config rules to check bucket settings and configure automatic remediation using AWS Systems Manager documents..
Why this is the answer
AWS Config is the most suitable service here because it continuously monitors and records AWS resource configurations, including S3 buckets, and evaluates them against desired configurations. You can define custom Config rules to check for encryption, logging, versioning, and public access settings. When a non-compliant bucket is detected, AWS Config can trigger automatic remediation actions using AWS Systems Manager Automation documents. This ensures ongoing compliance for both existing and newly created buckets. CloudTrail logs API activity but doesn't enforce configurations or provide built-in remediation for configuration drift. Trusted Advisor offers recommendations but isn't designed for continuous compliance enforcement and automatic remediation of configuration changes. While Systems Manager Automation documents are used for remediation, Systems Manager itself doesn't provide the continuous monitoring and evaluation capabilities needed to detect non-compliant S3 bucket configurations; AWS Config is required for that.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed