AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationMedium

A financial institution needs to ensure that all Amazon S3 buckets containing sensitive customer data are encrypted at rest with AWS Key Management Service (KMS) and are not publicly accessible. Any deviation from these requirements must be automatically remediated. Which AWS service and configuration can achieve this with the least administrative effort?

  1. AConfigure S3 bucket policies to enforce encryption and block public access, and use CloudWatch Alarms to monitor S3 bucket metrics.
  2. BEnable Amazon Macie to discover sensitive data in S3 buckets and then manually apply encryption and public access controls.
  3. CUse AWS Config rules with auto-remediation actions targeting `s3-bucket-server-side-encryption-enabled` and `s3-bucket-public-read-prohibited` rules.
  4. DImplement a custom AWS Lambda function triggered by Amazon S3 PutObject events to check encryption and public access, then remediate.
Show answer & explanation

Correct answer: C. Use AWS Config rules with auto-remediation actions targeting `s3-bucket-server-side-encryption-enabled` and `s3-bucket-public-read-prohibited` rules.

AWS Config rules with auto-remediation are specifically designed for this scenario. They can continuously monitor S3 buckets for compliance with encryption and public access requirements and automatically trigger remediation actions, minimizing administrative effort.

Why the other options are wrong

  • A. S3 bucket policies enforce the rules, but CloudWatch Alarms monitor metrics, not policy compliance directly, and do not provide auto-remediation for non-compliant existing buckets.
  • B. Amazon Macie is for sensitive data discovery, not for enforcing and auto-remediating encryption/public access policies. Manual remediation is not desired.
  • D. Custom Lambda functions require development and maintenance, increasing administrative overhead compared to managed Config rules.

AWS Config Auto-Remediation

AWS Config provides managed rules to evaluate AWS resource configurations for compliance. When integrated with auto-remediation, it can automatically take corrective actions on non-compliant resources.

  • Continuously monitors resource configurations.
  • Uses managed rules or custom Lambda-backed rules.
  • Can trigger auto-remediation actions for non-compliant resources.
  • Helps enforce security and compliance policies at scale.

Memory trick: Config checks and fixes, for S3's security mix.

More Monitoring, Logging, and Remediation questions