A security audit found many unencrypted EBS volumes across multiple AWS accounts. You must encrypt those volumes and ensure future unencrypted volumes are detected automatically. The company also wants centralized compliance and security management across accounts. Which combination of actions should you take? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create an AWS Organization, deploy AWS Control Tower, enable the strongly recommended controls (guardrails), invite/join all accounts to the Organization, and organize accounts into OUs., For each unencrypted volume, create a snapshot, create a new encrypted volume from that snapshot, detach the unencrypted volume, and attach the new encrypted volume in its place..
Why this is the answer
The first correct option addresses centralized management and future detection. Creating an AWS Organization with AWS Control Tower provides a multi-account environment with governance and security best practices. Enabling strongly recommended guardrails within Control Tower helps enforce policies, including detecting and preventing unencrypted resources. This sets up the framework for centralized compliance. The second correct option describes the standard procedure for encrypting existing unencrypted EBS volumes. EBS volumes cannot be encrypted in-place; they must be snapshotted, and a new encrypted volume created from that snapshot. The incorrect option about mandatory controls is too restrictive; strongly recommended controls are more appropriate for comprehensive security. Using the AWS CLI to encrypt in place is not possible. Automatically encrypting via CloudTrail and EventBridge is not a direct capability for existing unencrypted volumes, and direct encryption of existing volumes is not supported.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed