A financial services company needs to ensure that all data stored in Amazon S3 buckets is encrypted at rest using customer-managed keys (CMKs) from AWS Key Management Service (KMS). They also need to automatically remediate any S3 bucket that is not configured with the required KMS encryption. Which AWS services should be combined to achieve this continuous compliance and auto-remediation?
- AAWS CloudTrail, Amazon EventBridge, and AWS Lambda
- BAmazon Macie, AWS Security Hub, and AWS Lambda
- CAWS Config, Amazon SNS, and AWS Step Functions
- DAWS Config, AWS Systems Manager Automation, and AWS Lambda
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Config, AWS Systems Manager Automation, and AWS Lambda
AWS Config can continuously monitor S3 bucket configurations for compliance with a rule that checks for KMS encryption. When a non-compliant resource is detected, AWS Config can trigger an AWS Systems Manager Automation document, which can then use an AWS Lambda function to execute the remediation steps (e.g., enabling default KMS encryption on the S3 bucket).
Why the other options are wrong
- A. CloudTrail records events, and EventBridge can trigger Lambda, but Config is specifically designed for continuous compliance checks and can integrate directly with Systems Manager Automation for remediation.
- B. Macie is for data discovery and protection, and Security Hub aggregates findings. While they contribute to security, they don't provide the direct continuous configuration compliance and auto-remediation capabilities needed here.
- C. SNS is for notifications, and Step Functions orchestrates workflows. While Lambda could be part of a Step Functions workflow, using Systems Manager Automation directly with Config for remediation is a more integrated and common pattern for this scenario, as it offers a managed way to run remediation actions.
AWS Config Auto-Remediation
AWS Config can be used to continuously audit resource configurations against compliance rules. When a resource becomes non-compliant, Config can trigger an AWS Systems Manager Automation document, which uses a Lambda function or other actions to automatically remediate the issue.
- Config detects non-compliance.
- Triggers Systems Manager Automation.
- Lambda performs remediation actions.
- Ensures continuous compliance with policies.
Memory trick: Config 'checks' the S3 lock, and if it's open, Systems Manager 'fixes' it with Lambda.