AWS SAP-C02 · Question 24 · Domain 2.1: Deployment Strategy
A company requires that all infrastructure deployments are scanned for security vulnerabilities and compliance violations before being provisioned in AWS. They use AWS CloudFormation. How can this be automated in their CI/CD pipeline?
Answer options:
Use AWS Config rules to evaluate the resources after deployment.
Integrate AWS CloudFormation Guard in the pipeline to evaluate templates against policy rules before deployment.
Use Amazon Inspector to scan the CloudFormation templates.
Use AWS Trusted Advisor to block non-compliant deployments.
75 questions · hints · full answers · grading