A compliance officer needs to verify that all Amazon S3 buckets in their AWS organization are configured with server-side encryption and that public access is blocked. They also need to ensure that this compliance posture is continuously maintained across all existing and newly created accounts. Which AWS service should be used to achieve this continuous monitoring and enforcement?
- AAWS Config with conformance packs for continuous monitoring and AWS Lambda for automated remediation.
- BAWS CloudTrail for auditing S3 bucket changes and Amazon EventBridge for alerts.
- CAWS Trusted Advisor for security checks and manual remediation.
- DAWS Organizations Service Control Policies (SCPs) to deny S3 bucket creation without encryption and allow public access.
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Config with conformance packs for continuous monitoring and AWS Lambda for automated remediation.
AWS Config provides continuous monitoring of resource configurations against desired rules. Conformance packs allow deploying a collection of Config rules to multiple accounts. Combining this with AWS Lambda for automated remediation can ensure that non-compliant S3 buckets are automatically encrypted and public access is blocked, meeting the continuous monitoring and enforcement requirement.
Why the other options are wrong
- B. CloudTrail audits API calls, and EventBridge can trigger alerts, but this combination provides detection and notification, not continuous enforcement or automated remediation of the configuration itself.
- C. Trusted Advisor provides checks but requires manual remediation and doesn't offer continuous enforcement across an organization.
- D. SCPs can prevent the creation of non-compliant S3 buckets, but they cannot remediate existing non-compliant buckets or continuously monitor and enforce encryption and public access settings on buckets after creation or modification. Also, SCPs are deny-lists, so denying 'allow public access' is not how they directly block public access.
Continuous Compliance with AWS Config and Lambda
AWS Config continuously monitors AWS resource configurations for compliance. When combined with AWS Lambda, it can automatically remediate non-compliant resources, ensuring a desired security posture is maintained.
- AWS Config assesses resource configurations against rules.
- Conformance Packs deploy rules across an organization.
- AWS Lambda can be triggered by Config to automate remediation.
Memory trick: Config & Lambda: The Automated Compliance Patrol.