AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium
A DevOps team is managing an application that uses several AWS services, including Amazon EC2 instances, Amazon RDS databases, and Amazon S3 buckets. They use AWS CloudFormation to provision and manage these resources. The team needs to ensure that all CloudFormation templates adhere to strict security and compliance policies before deployment. Specifically, they must prevent the deployment of EC2 instances with public IP addresses and S3 buckets without server-side encryption. What is the MOST efficient way to automate the enforcement of these policies during the CloudFormation stack creation or update process?
- AUtilize AWS CloudFormation Guard to define rules and integrate it into a CI/CD pipeline to validate templates before deployment.
- BImplement a custom Lambda function triggered by CloudFormation stack events to validate resource properties post-deployment and rollback if non-compliant.
- CManually review each CloudFormation template for compliance with security policies before allowing it to be merged into the main branch.
- DCreate an AWS Config rule to continuously monitor deployed resources for compliance and remediate non-compliant resources.
Show answer & explanationAnswer & explanation
Correct answer: A. Utilize AWS CloudFormation Guard to define rules and integrate it into a CI/CD pipeline to validate templates before deployment.
AWS CloudFormation Guard is a policy-as-code tool that allows defining rules to check CloudFormation templates for compliance before deployment. Integrating it into a CI/CD pipeline enables automated policy enforcement, preventing non-compliant infrastructure from being provisioned. This is more efficient and proactive than post-deployment checks or manual reviews.
Why the other options are wrong
- B. This approach is reactive, as it requires resources to be deployed first, then checked, and potentially rolled back, which is less efficient than pre-deployment validation.
- C. Manual review is prone to human error, time-consuming, and does not scale well, making it inefficient for enforcing strict policies in a DevOps environment.
- D. AWS Config monitors deployed resources for compliance, which is reactive. It does not prevent the deployment of non-compliant resources in the first place.
CloudFormation Guard
A policy-as-code tool that allows developers to define rules to validate CloudFormation templates against organizational policies before deployment.
- Enforces security and compliance policies pre-deployment.
- Integrates into CI/CD pipelines for automated checks.
- Prevents non-compliant infrastructure provisioning.
Memory trick: Guard your templates before they build the wrong thing.