AWS Certified DevOps Engineer – ProfessionalIncident and Event ResponseHard

A company uses AWS Organizations to manage multiple AWS accounts and has a strict security policy requiring all S3 buckets to be encrypted at rest. They need to implement a mechanism that automatically identifies non-compliant S3 buckets across all accounts and remediates them by enabling default encryption. The solution must be centrally managed and scalable. Which combination of AWS services should be used?

  1. AAWS Security Hub to detect non-compliant buckets, followed by manual remediation steps by the security team.
  2. BAWS Config with a custom rule and an associated remediation action, deployed via AWS Organizations integration.
  3. CAWS CloudTrail to monitor S3 bucket creation events, triggering an AWS Lambda function to check and encrypt.
  4. DAmazon Macie to identify unencrypted sensitive data in S3, and then manually apply encryption.
Show answer & explanation

Correct answer: B. AWS Config with a custom rule and an associated remediation action, deployed via AWS Organizations integration.

AWS Config, integrated with AWS Organizations, allows for the central deployment of compliance rules across multiple accounts. A custom Config rule can detect S3 buckets without default encryption, and an associated remediation action (often a System Manager Automation document or Lambda function) can automatically enable default encryption, ensuring scalable and automated compliance.

Why the other options are wrong

  • A. Security Hub detects issues but doesn't provide automated remediation. Manual steps contradict the automation requirement.
  • C. While CloudTrail and Lambda can react to new bucket creation, Config provides continuous monitoring of *existing* and new buckets, and its remediation features are more integrated for compliance at scale across accounts.
  • D. Macie is for sensitive data discovery, not for enforcing default encryption on buckets. Manual application of encryption contradicts automation.

Cross-Account Config Remediation

This involves using AWS Config rules deployed via AWS Organizations to continuously monitor resource compliance across multiple accounts and automatically trigger remediation actions for non-compliant resources.

  • Centralized compliance management.
  • Automated detection and remediation of drift.
  • Scalable across many AWS accounts.

Memory trick: Organizations centralizes the rule, Config finds the non-compliant tool, then automates the fix, no longer a fool.

More Incident and Event Response questions