Which solution will, with minimal development effort, detect AWS service misconfigurations across all organization accounts near real time, automatically remediate within 15 minutes, and provide a centralized dashboard with accurate timestamps?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable the AWS Config recorder in all accounts to detect noncompliance, enable Security Hub (no default standards) across accounts, create AWS Config managed and custom rules with automatic remediation via Config conformance packs, and use a Security Hub administrator account for a centralized dashboard..
Why this is the answer
The correct solution leverages AWS Config and Security Hub for comprehensive, near real-time misconfiguration detection, automated remediation, and centralized reporting. AWS Config recorders continuously monitor resource configurations across all accounts. AWS Config rules (managed and custom) define compliance checks, and conformance packs allow for easy deployment and management of these rules, including automatic remediation actions. Security Hub, when enabled across accounts and configured with an administrator account, aggregates findings from Config and other services, providing a centralized dashboard with accurate timestamps. This approach minimizes development effort by utilizing native AWS services designed for this purpose. Other options are less efficient or comprehensive: CloudFormation drift detection only applies to resources managed by CloudFormation, not all AWS services. CloudTrail with Athena or CloudWatch Logs for detection requires significant custom development for defining noncompliance and remediation logic, and may not be near real-time.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed