AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsMedium

A large enterprise uses AWS Organizations to manage multiple AWS accounts. They have a strict security policy requiring that all S3 buckets in specific accounts must deny public access and enforce encryption at rest. The security team needs an automated solution to continuously monitor and enforce these compliance rules across new and existing S3 buckets without manual intervention. Which AWS service combination should be used to achieve this goal efficiently?

  1. AAWS CloudFormation and AWS Organizations Service Control Policies (SCPs).
  2. BAmazon S3 Access Analyzer and AWS Security Hub.
  3. CAWS Config and AWS Lambda functions.
  4. DAWS CloudTrail and Amazon EventBridge rules.
Show answer & explanation

Correct answer: C. AWS Config and AWS Lambda functions.

AWS Config can continuously monitor S3 bucket configurations against predefined rules (e.g., 's3-bucket-public-read-prohibited', 's3-bucket-encrypted'). When a non-compliant bucket is detected, AWS Config can trigger an AWS Lambda function to automatically remediate the issue, such as applying the correct bucket policy or encryption settings.

Why the other options are wrong

  • A. CloudFormation provisions resources, and SCPs prevent certain actions, but they don't continuously monitor and remediate misconfigurations on existing or manually created resources.
  • B. S3 Access Analyzer identifies public and cross-account access, and Security Hub aggregates findings, but neither directly enforces configuration or remediates issues without other services.
  • D. CloudTrail logs API activity, and EventBridge can react to events, but this combination primarily monitors and alerts, not automatically remediates configuration drift without additional Lambda functions.

Continuous Compliance Enforcement

Using AWS Config to monitor resource configurations against compliance rules and AWS Lambda to automatically remediate non-compliant resources.

  • AWS Config detects policy violations.
  • AWS Lambda performs automated remediation.
  • Ensures continuous compliance without manual intervention.

Memory trick: Config checks the rules, Lambda fixes the tools.

More Network Management and Operations questions