AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A compliance officer needs to ensure that all Amazon S3 buckets across their AWS organization are configured with block public access settings enabled and that server access logging is always turned on. Any new or existing bucket that violates these rules must be automatically flagged and, if possible, remediated. Which combination of AWS services offers the most effective solution for continuous auditing and automated remediation of these S3 configurations?

  1. AAWS CloudTrail and Amazon EventBridge
  2. BAmazon Macie and AWS Security Hub
  3. CAWS Config with Custom Rules and AWS Lambda
  4. DAWS Inspector and AWS Systems Manager Automation
Show answer & explanation

Correct answer: C. AWS Config with Custom Rules and AWS Lambda

AWS Config is ideal for continuous auditing of resource configurations against desired states. By defining custom Config rules for S3 bucket public access and access logging, and integrating with AWS Lambda functions, any non-compliant buckets can be automatically detected and remediated, ensuring continuous compliance across the organization.

Why the other options are wrong

  • A. CloudTrail logs API activity, and EventBridge can react to events, but this combination primarily focuses on event-driven actions rather than continuous configuration auditing and direct remediation of resource properties like Config.
  • B. Amazon Macie discovers sensitive data in S3 and identifies data access anomalies, while Security Hub aggregates findings. Neither directly provides continuous configuration auditing or automated remediation for bucket settings.
  • D. AWS Inspector assesses EC2 vulnerabilities, and Systems Manager Automation can perform operational tasks, but this combination is not designed for continuous, organization-wide S3 bucket configuration auditing and remediation.

Config & Lambda for S3 Compliance

AWS Config continuously monitors S3 bucket configurations, using custom rules to identify non-compliance, and triggers AWS Lambda for automated remediation.

  • AWS Config provides continuous monitoring of S3 bucket configurations.
  • Custom Config rules can enforce specific S3 settings (e.g., block public access, logging).
  • AWS Lambda functions enable automated remediation of non-compliant S3 buckets.
  • Integrates with AWS Organizations for multi-account compliance.

Memory trick: Config checks S3, Lambda fixes it, making S3 compliant.

More Network Security, Compliance, and Governance questions