AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationHard
A company is using AWS CloudFormation to provision its infrastructure. They want to ensure that all CloudFormation templates adhere to specific security and compliance standards before deployment. This includes checks for insecure configurations, proper tagging, and resource limits. Which AWS service can be integrated into the CI/CD pipeline to automate these checks?
- AAWS CloudFormation Guard
- BAmazon Inspector
- CAWS Config
- DAWS Trusted Advisor
Show answer & explanationAnswer & explanation
Correct answer: A. AWS CloudFormation Guard
AWS CloudFormation Guard is a policy-as-code service that allows developers to define rules for CloudFormation templates. It can be integrated into CI/CD pipelines to validate templates against security, compliance, and best practice policies *before* deployment, preventing non-compliant resources from being provisioned.
Why the other options are wrong
- B. Amazon Inspector is a vulnerability management service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure, not CloudFormation templates.
- C. AWS Config evaluates resources *after* they are deployed, not before. It can detect non-compliance but doesn't prevent it during provisioning.
- D. Trusted Advisor provides recommendations for cost optimization, security, fault tolerance, and performance, but it's not a policy engine for CloudFormation templates in a CI/CD pipeline.
AWS CloudFormation Guard
An open-source policy-as-code tool that allows developers to define and enforce rules for CloudFormation templates to ensure compliance and security before deployment.
- Validates templates against custom policies.
- Integrates into CI/CD pipelines.
- Supports security, compliance, and best practice checks.
Memory trick: Guard protects templates, policies stand tall.