AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationHard

A financial institution needs to ensure that all Amazon S3 buckets containing sensitive customer data are encrypted at rest using AWS Key Management Service (KMS) with customer-managed keys (CMKs). They also need to automatically remediate any non-compliant buckets. Which AWS service combination provides this capability?

  1. AAWS CloudTrail to log S3 PUT events and an EventBridge rule to trigger encryption.
  2. BAmazon Macie to discover sensitive data and encrypt non-compliant S3 buckets.
  3. CAmazon S3 default encryption settings combined with S3 Bucket Policies.
  4. DAWS Config with a custom rule and an AWS Lambda function for auto-remediation.
Show answer & explanation

Correct answer: D. AWS Config with a custom rule and an AWS Lambda function for auto-remediation.

AWS Config can monitor S3 buckets for compliance with specific encryption requirements (e.g., using KMS CMKs). When a non-compliant bucket is detected, an AWS Config rule can be configured to trigger an AWS Lambda function. This Lambda function can then automatically modify the S3 bucket policy or default encryption settings to enforce encryption with the required KMS CMK, providing automated remediation.

Why the other options are wrong

  • A. CloudTrail logs events, and EventBridge can trigger actions, but this approach is more reactive to specific PUT events and less comprehensive for continuous compliance monitoring and auto-remediation of existing or newly created non-compliant buckets.
  • B. Amazon Macie discovers sensitive data but does not automatically remediate encryption settings. It mainly provides alerts.
  • C. While S3 default encryption and bucket policies can enforce encryption, this option does not include a mechanism for *detecting* and *automatically remediating* non-compliant buckets that might be created or configured incorrectly.

S3 Encryption Auto-Remediation

Automate the detection and remediation of non-compliant Amazon S3 buckets that do not meet specific encryption-at-rest requirements, such as using AWS KMS Customer-Managed Keys (CMKs).

  • AWS Config monitors for compliance.
  • Lambda functions perform remediation actions.
  • Ensures continuous security posture.

Memory trick: Config sees the non-compliance, Lambda automatically fixes the S3 encryption.

More Monitoring, Logging, and Remediation questions