AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeHard

A security-conscious organization uses AWS CloudFormation to manage its infrastructure. They have a strict policy that all Amazon S3 buckets must have server-side encryption enabled and be configured with public access blocked. Before deploying any CloudFormation stack, they need an automated way to validate that the S3 bucket resources defined in the template adhere to these security policies, failing the deployment if they don't. Which CloudFormation feature can provide this proactive policy enforcement during template validation?

  1. ACloudFormation Guard
  2. BCloudFormation Change Sets
  3. CAWS Config Rules with remediation
  4. DCloudFormation Stack Policies
Show answer & explanation

Correct answer: A. CloudFormation Guard

CloudFormation Guard is an open-source policy-as-code tool that allows defining policies to validate CloudFormation templates against security and compliance rules *before* deployment. It can proactively identify and reject templates that do not meet the specified S3 bucket encryption and public access policies, failing the deployment early in the pipeline.

Why the other options are wrong

  • B. Change Sets preview changes but don't enforce policies or fail deployments based on policy violations.
  • C. AWS Config Rules detect non-compliance *after* resources are deployed or changed; they are reactive, not proactive template validation.
  • D. Stack Policies prevent unintended updates/deletions on *existing* resources, not validate templates pre-deployment.

CloudFormation Guard

CloudFormation Guard is an open-source tool that provides a policy-as-code language to define rules for validating CloudFormation templates. It helps ensure that infrastructure deployments adhere to security, compliance, and operational best practices by proactively checking templates before they are deployed.

  • Policy-as-code for CloudFormation templates.
  • Proactive validation *before* deployment.
  • Identifies non-compliant resources in templates.
  • Integrates into CI/CD pipelines to fail early.

Memory trick: CloudFormation Guard is your template's security checkpoint.

More Configuration Management and Infrastructure as Code questions