A company uses AWS Organizations to manage multiple AWS accounts and has a strict security policy requiring all S3 buckets to be encrypted at rest. They need to implement a mechanism that automatically identifies non-compliant S3 buckets across all accounts and remediates them by enabling default encryption. The solution must be centrally managed and scalable. Which combination of AWS services should be used?
- AAWS Security Hub to detect non-compliant buckets, followed by manual remediation steps by the security team.
- BAWS Config with a custom rule and an associated remediation action, deployed via AWS Organizations integration.
- CAWS CloudTrail to monitor S3 bucket creation events, triggering an AWS Lambda function to check and encrypt.
- DAmazon Macie to identify unencrypted sensitive data in S3, and then manually apply encryption.
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Config with a custom rule and an associated remediation action, deployed via AWS Organizations integration.
AWS Config, integrated with AWS Organizations, allows for the central deployment of compliance rules across multiple accounts. A custom Config rule can detect S3 buckets without default encryption, and an associated remediation action (often a System Manager Automation document or Lambda function) can automatically enable default encryption, ensuring scalable and automated compliance.
Why the other options are wrong
- A. Security Hub detects issues but doesn't provide automated remediation. Manual steps contradict the automation requirement.
- C. While CloudTrail and Lambda can react to new bucket creation, Config provides continuous monitoring of *existing* and new buckets, and its remediation features are more integrated for compliance at scale across accounts.
- D. Macie is for sensitive data discovery, not for enforcing default encryption on buckets. Manual application of encryption contradicts automation.
Cross-Account Config Remediation
This involves using AWS Config rules deployed via AWS Organizations to continuously monitor resource compliance across multiple accounts and automatically trigger remediation actions for non-compliant resources.
- Centralized compliance management.
- Automated detection and remediation of drift.
- Scalable across many AWS accounts.
Memory trick: Organizations centralizes the rule, Config finds the non-compliant tool, then automates the fix, no longer a fool.