AWS Certified DevOps Engineer - Professional DOP-C02
By Amazon · Question Mode
QuestionQ13
Security and Compliance
A company uses AWS Organizations to centrally administer its AWS accounts. It enabled AWS Config in every member account by using AWS CloudFormation StackSets. The company configured trusted access in Organizations for AWS Config and designated a member account as the delegated administrator account for AWS Config.
A DevOps engineer must implement a new security policy. The policy must require all existing and future AWS member accounts to use a shared baseline of AWS Config rules, including remediation actions, that is managed from a central account. Non-administrator users with access to member accounts must be unable to modify this shared baseline of AWS Config rules deployed in each member account.
Which solution meets these requirements?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion