AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationHard
A compliance team requires that all Amazon S3 buckets are configured with server access logging enabled to a centralized logging bucket. This policy must be automatically enforced across all new and existing S3 buckets in specific AWS accounts, and non-compliant buckets must be automatically remediated. Which combination of AWS services provides the most robust and automated solution for both detection and remediation?
- AAmazon EventBridge and AWS Step Functions
- BAWS Config Rules and AWS Systems Manager Automation
- CAWS CloudTrail and AWS Lambda
- DAWS Security Hub and AWS GuardDuty
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Config Rules and AWS Systems Manager Automation
AWS Config Rules can detect non-compliant S3 buckets (e.g., missing server access logging). When a non-compliant resource is detected, AWS Config can trigger an AWS Systems Manager Automation document, which can then perform the necessary steps to enable server access logging, providing automated remediation.
Why the other options are wrong
- A. EventBridge and Step Functions can build workflows, but Config Rules are specifically designed for continuous compliance detection.
- C. CloudTrail logs API activity, but doesn't automatically detect or remediate non-compliant configurations.
- D. Security Hub aggregates findings, and GuardDuty is a threat detection service; neither provides automated configuration remediation.
AWS Config with Systems Manager Automation
A combination of services where AWS Config detects non-compliant resource configurations and triggers Systems Manager Automation to automatically remediate them.
- Config Rules continuously evaluate resource compliance.
- Automation documents define remediation steps.
- Provides automated detection and self-healing for non-compliant resources.
Memory trick: Config checks, Automation corrects, compliance connects.