QuestionQ19

Data Protection

A company uses AWS Config rules to find Amazon S3 buckets that do not comply with the company’s data protection policy. The S3 buckets are hosted across several AWS Regions and several AWS accounts. The accounts belong to an organization in AWS Organizations.

The company requires a solution that remediates the organization’s existing noncompliant S3 buckets and any noncompliant S3 buckets created in the future.

Which solution meets these requirements?

Explanation

AWS Config aggregators can collect configuration and compliance data from an AWS Organizations organization across multiple accounts and Regions. A Lambda-based response to AWS Config noncompliance findings can perform corrective changes, such as reconfiguring or deleting an S3 bucket, so it can remediate both existing resources and subsequently created noncompliant resources. An SCP can prevent allowed actions but cannot remediate buckets that already exist.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!