Question 1 · choose 1
A security team wants S3 buckets that allow public read access to be fixed automatically within minutes in every account, and wants the team's channel notified each time a bucket becomes noncompliant. Which approach meets these requirements?
- AConfig rule auto-remediation via Automation, plus an EventBridge rule to SNS
- BA weekly review of the Trusted Advisor S3 bucket permissions check
- CAn AWS Config aggregator in the security account that collects all accounts
- DAmazon Macie automated sensitive data discovery across every account
Show the answer and why
AConfig rule auto-remediation via Automation, plus an EventBridge rule to SNS
Correct
Config remediation runs Automation documents on noncompliant resources, automatically if chosen, and Config compliance changes can be routed to targets through EventBridge.
BA weekly review of the Trusted Advisor S3 bucket permissions check
Incorrect
A weekly manual review neither fixes buckets within minutes nor sends a notification for each change.
CAn AWS Config aggregator in the security account that collects all accounts
Incorrect
An aggregator gives a read-only view of compliance data; it cannot change resources.
DAmazon Macie automated sensitive data discovery across every account
Incorrect
Macie looks for sensitive data and reports bucket access settings; it does not change bucket permissions.
Detection, remediation and notification are three separate parts: a Config rule, a remediation action, and an EventBridge rule on compliance changes.
AWS documentation