A SysOps administrator must ensure that every current and future Amazon S3 bucket in the account has server access logging enabled. If a bucket is found without logging, an automated process must enable logging on that bucket. Which solution satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Use the AWS Config managed rule s3-bucket-logging-enabled and add a remediation action that runs the AWS-ConfigureS3BucketLogging Systems Manager Automation runbook to enable logging..
Why this is the answer
The correct solution leverages AWS Config for continuous compliance and AWS Systems Manager Automation for remediation. The s3-bucket-logging-enabled AWS Config managed rule continuously monitors S3 buckets for compliance with server access logging. When a non-compliant bucket is detected, the associated remediation action, running the AWS-ConfigureS3BucketLogging Systems Manager Automation runbook, automatically enables logging for that bucket. This provides an automated, scalable, and proactive solution. Running an AWS Trusted Advisor check is for recommendations, not automated remediation. An S3 bucket policy cannot enforce server access logging; it controls access to the bucket. While an AWS Lambda function could enable logging, using the AWS-ConfigureS3BucketLogging Systems Manager Automation runbook is a pre-built, robust, and recommended approach for this specific task, simplifying the solution compared to writing and maintaining a custom Lambda function.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed