A DevOps team manages a critical production application deployed across multiple AWS accounts and regions. All infrastructure is provisioned using CloudFormation. To prevent accidental or unauthorized modifications to sensitive resources like production databases or core network components, they need a mechanism to ensure that only specific, pre-approved CloudFormation template updates are allowed for these resources. Any attempt to modify or delete these critical resources outside of an approved process should be immediately rejected. Which combination of AWS services and CloudFormation features should the team implement?
- AAWS CloudTrail for auditing and Amazon EventBridge for alerting on unauthorized API calls.
- BCloudFormation Stack Policies and AWS Organizations Service Control Policies (SCPs).
- CAWS Systems Manager Change Manager and CloudFormation Hooks.
- DAWS Config Rules for drift detection and CloudFormation Change Sets for review.
Show answer & explanationAnswer & explanation
Correct answer: B. CloudFormation Stack Policies and AWS Organizations Service Control Policies (SCPs).
CloudFormation Stack Policies prevent unintended updates or deletions of specific resources within a stack, ensuring only approved template updates can affect them. AWS Organizations Service Control Policies (SCPs) act as guardrails at the organizational level, denying actions even if a user has permissions, effectively preventing unauthorized modifications or deletions across accounts, thus providing a robust, multi-layered prevention mechanism.
Why the other options are wrong
- A. CloudTrail and EventBridge are for auditing and alerting *after* an event, not for preventing the event itself.
- C. Change Manager is for managing operational changes, and CloudFormation Hooks are for custom logic during provisioning, neither primarily prevents unauthorized resource modifications/deletions at the policy level.
- D. Config Rules detect drift after it occurs, and Change Sets only preview; neither actively prevents unauthorized changes or deletions.
Stack Policies & SCPs for Prevention
CloudFormation Stack Policies prevent unintended updates or deletions of specific stack resources. AWS Organizations Service Control Policies (SCPs) act as preventative guardrails at the account or organizational level, denying actions even if an IAM user/role has explicit permissions, providing a strong, multi-layered defense against unauthorized infrastructure modifications.
- Stack Policies: resource-level prevention within a stack.
- SCPs: account/organizational-level prevention, overriding IAM.
- Together, they offer robust, proactive protection for critical infrastructure.
- Preventative controls, not just detective.
Memory trick: Stack Policies guard the resources, SCPs guard the accounts.