QuestionQ1

Security and Compliance

A company uses AWS Organizations to manage multiple accounts. Information security policies require that every unencrypted Amazon EBS volume be designated as non-compliant. A DevOps engineer must deploy the solution automatically and ensure that this compliance check is always in place.

Which solution will accomplish this?

Explanation

AWS Config’s ENCRYPTED_VOLUMES managed rule reports attached EBS volumes as NON_COMPLIANT when they are unencrypted. An organization AWS Config rule centrally deploys the rule across member accounts, including accounts that subsequently join the organization. An SCP that denies actions to stop or delete AWS Config helps ensure the ongoing compliance evaluation cannot be disabled by member accounts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!