The company uses RDS for all databases and AWS Control Tower to manage accounts. All databases must be encrypted at rest. The security engineer must be notified about any noncompliant (unencrypted) RDS instances across accounts. Which solution provides the most operational efficiency?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable the optional detective control (guardrail) in AWS Control Tower to check whether RDS storage is encrypted. Create an SNS topic in the audit account. Create an EventBridge rule to filter Control Tower noncompliant events and forward them to the SNS topic, then subscribe the security engineer’s email..
Why this is the answer
The correct solution leverages AWS Control Tower's built-in capabilities for multi-account governance. Enabling the optional detective guardrail for RDS encryption automatically checks compliance across all managed accounts without requiring custom code or deployments in each account. This provides the highest operational efficiency. Routing these noncompliant events via EventBridge to an SNS topic in the audit account centralizes notifications and ensures the security engineer receives timely alerts. Incorrect options: Deploying Lambda functions or custom Config rules to every account using StackSets adds unnecessary complexity and management overhead compared to Control Tower's integrated guardrails. Launching an EC2 instance with a cron job is a highly inefficient and unscalable solution. It requires managing an EC2 instance, developing custom scripts, and lacks the native integration and real-time detection of AWS services.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed