AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceMedium

A financial services company is migrating its on-premises applications to AWS. Due to strict regulatory requirements (e.g., PCI DSS, HIPAA), all data at rest must be encrypted, and all data in transit must use TLS 1.2 or higher. The DevOps team needs to automate the enforcement of these encryption standards across all newly provisioned AWS resources, such as S3 buckets, EBS volumes, and EC2 instances, and report on any non-compliant resources. Which AWS service should the team use to continuously monitor and automatically remediate non-compliant resources?

  1. AAWS Config
  2. BAWS Trusted Advisor
  3. CAWS GuardDuty
  4. DAWS CloudTrail
Show answer & explanation

Correct answer: A. AWS Config

AWS Config provides a detailed view of the configuration of AWS resources in your account. It continuously monitors and records configuration changes and can evaluate recorded configurations against desired configurations, allowing for automated remediation of non-compliant resources using AWS Systems Manager Automation documents or Lambda functions.

Why the other options are wrong

  • B. Trusted Advisor provides recommendations for cost optimization, performance, security, and fault tolerance but does not continuously monitor or automatically remediate non-compliant resources.
  • C. GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not for configuration compliance.
  • D. CloudTrail logs API activity and events but does not enforce or remediate configuration compliance.

AWS Config

A service that enables you to assess, audit, and evaluate the configurations of your AWS resources. Config continuously monitors and records your AWS resource configurations and allows you to automate the evaluation of recorded configurations against desired configurations.

  • Continuous monitoring of AWS resource configurations.
  • Evaluates compliance against rules.
  • Supports automated remediation via Systems Manager or Lambda.

Memory trick: Config checks and corrects, ensuring compliance constantly.

More Security and Compliance questions