AWS SAP-C02 · Question 11 · Domain 3.1: Operational Excellence
A company wants to improve operational excellence by automatically remediating non-compliant AWS resources. For example, if an S3 bucket is created without public access block enabled, it should be automatically corrected. Which solution achieves this?
Answer options:
Use AWS CloudTrail to trigger an AWS Lambda function that deletes the bucket.
Use AWS Config rules to detect non-compliance and trigger AWS Systems Manager Automation documents for remediation.
Use Amazon GuardDuty to detect the misconfiguration and block access via WAF.
Use AWS Trusted Advisor to automatically apply the correct settings.
75 questions · hints · full answers · grading