AWS Certified DevOps Engineer – ProfessionalIncident and Event ResponseMedium

A financial institution uses AWS Organizations to manage multiple accounts, with strict security and compliance requirements. They need to ensure that all critical S3 buckets across all accounts have encryption enabled by default and are not publicly accessible. If a new S3 bucket is created without these settings, it must be automatically remediated. Which combination of AWS services should the DevOps team implement to achieve this? (Select TWO correct answers, but only one option combines the two correct services.)

  1. AAmazon S3 Event Notifications and Amazon SNS
  2. BAWS Systems Manager and AWS CloudTrail
  3. CAWS GuardDuty and AWS Security Hub
  4. DAWS Config and AWS Lambda
Show answer & explanation

Correct answer: D. AWS Config and AWS Lambda

AWS Config can continuously monitor resource configurations and detect non-compliant S3 buckets. When non-compliance is detected, AWS Config can trigger an AWS Lambda function to automatically remediate the bucket by enabling encryption and blocking public access.

Why the other options are wrong

  • A. Amazon S3 Event Notifications can trigger actions on S3 events (e.g., object creation), but they don't inherently check for compliance of bucket-level settings or perform cross-account remediation. Amazon SNS is a messaging service.
  • B. AWS Systems Manager is for operational tasks and automation, but not for continuous compliance monitoring or event-driven remediation. CloudTrail logs API activity but doesn't perform compliance checks or remediation.
  • C. AWS GuardDuty is a threat detection service, and AWS Security Hub aggregates security findings. Neither directly provides automated configuration compliance enforcement and remediation in the way Config and Lambda do.

Automated Remediation with AWS Config and Lambda

This pattern involves using AWS Config to continuously monitor resource compliance and triggering an AWS Lambda function to automatically correct non-compliant resources.

  • AWS Config detects non-compliance.
  • Lambda function performs the remediation.
  • Ensures continuous adherence to security and operational standards.

Memory trick: Config checks the rules, Lambda fixes the tools.

More Incident and Event Response questions