QuestionQ51

Security and Compliance

A CloudOps engineer must make sure that every current and future Amazon S3 bucket belonging to a company has logging enabled. If an S3 bucket does not have logging enabled, an automated process must turn on logging for that S3 bucket.

Which solution meets these requirements?

Explanation

The AWS Config s3-bucket-logging-enabled managed rule checks S3 buckets and reports a bucket as NON_COMPLIANT when logging is not enabled. A remediation action that invokes the AWS-ConfigureS3BucketLogging AWS Systems Manager Automation runbook can automatically enable S3 server access logging, covering both existing buckets and buckets evaluated after future configuration changes.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!