AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeHard
A company uses AWS CloudFormation to deploy a web application. They need to ensure that specific compliance requirements are met for all newly created S3 buckets, such as encryption at rest and public access blocking. If a CloudFormation template attempts to create an S3 bucket that does not meet these compliance rules, the deployment should fail. Which AWS service can be integrated with CloudFormation to enforce these preventative compliance checks?
- AAWS Config rules
- BAWS Service Catalog with constraints
- CAWS Security Hub
- DAWS CloudFormation Hooks
Show answer & explanationAnswer & explanation
Correct answer: D. AWS CloudFormation Hooks
AWS CloudFormation Hooks allow you to invoke custom logic (e.g., AWS Lambda functions) during specific lifecycle events of a CloudFormation deployment, such as before resource creation. This enables preventative compliance checks, where a hook can analyze the template or proposed resource properties and fail the deployment if compliance rules are violated.
Why the other options are wrong
- A. AWS Config rules primarily perform *detective* controls, assessing compliance *after* resources are created. It can't prevent creation directly during a CloudFormation deployment.
- B. AWS Service Catalog allows defining constraints on products, but it's for end-user provisioning, not for enforcing compliance within arbitrary CloudFormation deployments across a development team.
- C. AWS Security Hub aggregates security findings and provides a centralized view of security posture, but it doesn't directly prevent CloudFormation deployments based on compliance rules.
CloudFormation Hooks
A CloudFormation feature that allows you to invoke custom logic (e.g., AWS Lambda functions) during specific stack deployment lifecycle events, enabling preventative controls and custom validations.
- Invoked before resource creation, update, or deletion.
- Enables preventative compliance and security checks.
- Can fail stack operations if checks are not met.
Memory trick: CloudFormation Hooks, before you build, compliance checks must yield.