All S3 buckets must have server-side encryption enabled using AES-256 immediately upon creation, and existing unencrypted buckets must be brought into compliance. Which solution enforces AES-256 for new buckets and remediates existing buckets?
Choose an answer
Tap an option to check your answer.
Correct answer: Set up and enable the s3-bucket-server-side-encryption-enabled AWS Config managed rule, configure it to use the AWS-EnableS3BucketEncryption Systems Manager Automation runbook as the remediation action, and manually run re-evaluation to ensure existing buckets are compliant..
Why this is the answer
The s3-bucket-server-side-encryption-enabled AWS Config managed rule directly checks for S3 bucket encryption compliance. Integrating it with the AWS-EnableS3BucketEncryption Systems Manager Automation runbook provides an automated remediation for non-compliant buckets, addressing both existing and newly created non-compliant buckets. Manually re-evaluating ensures existing buckets are immediately checked. Creating a Lambda function invoked by EventBridge for periodic scanning (option 1) is less efficient and reactive than AWS Config's continuous monitoring. A Lambda function triggered by S3 creation events (option 3) only addresses new buckets, not existing non-compliant ones. An IAM policy (option 4) can prevent the creation of unencrypted buckets but won't remediate existing ones or enforce encryption on buckets created without the specific condition key if the policy isn't universally applied or circumvented.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed