Question 1 · choose 2
A platform team's pipeline deploys CloudFormation templates to many accounts. Before deployment, the build must fail when a template has invalid syntax or property values, and also when it breaks company security rules, such as S3 buckets without encryption, written by the security team as policy as code. Which tools should the pipeline run? (Choose TWO.)
- Acfn-lint against the CloudFormation resource specification
- BCloudFormation drift detection run against the deployed stacks
- CAWS CloudFormation Guard rules written in its DSL
- DAWS Config rules evaluated in each of the target accounts
- ECloudFormation StackSets with automatic deployment to new accounts
Show the answer and why
Acfn-lint against the CloudFormation resource specification
Correct
cfn-lint inspects template structure, syntax and allowed property values, which Guard does not do.
BCloudFormation drift detection run against the deployed stacks
Incorrect
Drift detection compares deployed resources with their templates after deployment; it does not test templates before deployment.
CAWS CloudFormation Guard rules written in its DSL
Correct
Guard is a policy-as-code tool that validates templates and other JSON or YAML data against rules written in its DSL.
DAWS Config rules evaluated in each of the target accounts
Incorrect
Config rules evaluate resources after they exist, not templates in the build.
ECloudFormation StackSets with automatic deployment to new accounts
Incorrect
StackSets deploy stacks across accounts. They do not check templates against security rules.
The two checks are complementary: cfn-lint for "is this a valid template?", Guard for "does it follow our rules?".
AWS documentation