Using AWS Control Tower and CloudFormation, the company requires that every S3 bucket created by CloudFormation in the multi-account environment must be encrypted with AWS KMS keys. Which approach enforces this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS Control Tower with a multi-account environment. Configure and enable proactive AWS Control Tower controls on all OUs with CloudFormation hooks..
Why this is the answer
The correct answer is to use AWS Control Tower with proactive controls and CloudFormation hooks. Proactive controls, specifically CloudFormation hooks, allow you to inspect and potentially prevent resource deployments before they are created. This ensures that any S3 bucket created via CloudFormation in the multi-account environment will be checked for KMS encryption compliance and blocked if non-compliant, thus enforcing the requirement. Using an AWS Organizations SCP to deny s3:PutObject based on encryption headers would only prevent objects from being uploaded without KMS encryption, not enforce that the bucket itself is created with KMS encryption. Detective controls in AWS Control Tower would only detect non-compliant buckets after they are created, not prevent their creation. An AWS Config organizational rule would also only detect non-compliance after the fact.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed