The company requires a recorded history of any changes to security groups and wants the SysOps administrator notified whenever a security group is modified. Which implementation accomplishes both goals?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable AWS Config to record security group changes, store configuration snapshots and history in an S3 bucket, create an SNS topic for configuration-change notifications, and subscribe the administrator's email to the topic..
Why this is the answer
The correct option uses AWS Config, which is specifically designed to record and evaluate configuration changes of AWS resources, including security groups. It stores this history, and can trigger Amazon SNS notifications for changes, allowing the administrator to be alerted via email. Incorrect options: Amazon Detective is a security service for investigating potential security issues, not for recording configuration changes or providing real-time alerts on resource modifications. AWS Systems Manager Change Manager is for managing operational changes to your application configuration and infrastructure, not for recording all configuration history of individual AWS resources like security groups. The other option involving Amazon Detective again misuses Detective's primary purpose. While it can store data in S3 and use SNS, it's not the service for tracking configuration changes.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed