exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 932 discussion

Exam question from Amazon's AWS-SysOps
Question #: 932
Topic #: 1
[All AWS-SysOps Questions]

A company's audit shows that users have been changing cost-related tags on Amazon EC2 instances after deployment. The company has an organization in
AWS Organizations with many AWS accounts.
The company needs a solution to detect the EC2 instances automatically. The solution must require the least possible operational overhead.
Which solution meets these requirements?

  • A. Use service control policies (SCPs) to track EC2 instances that do not have the required tags.
  • B. Use Amazon Inspector to run a report to identify EC2 instances that do not have the required tags.
  • C. Use an AWS Config rule to track EC2 instances that do not have the required tags.
  • D. Use AWS Well-Architected Tool (AWS WA Tool) to run a report to identify EC2 instances that do not have the required tags.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
albert_kuo
9 months, 1 week ago
Selected Answer: C
AWS Config allows you to create custom rules (AWS Config rules) to check the configuration of your AWS resources, including EC2 instances, against a set of desired configurations. By creating a custom AWS Config rule, you can track EC2 instances that do not have the required cost-related tags. When an EC2 instance is launched or modified and lacks the required tags, AWS Config can automatically detect this non-compliance and generate an evaluation result. This solution requires minimal operational overhead once the AWS Config rule is set up and enabled. AWS Config takes care of continuously monitoring the resources for compliance and automatically evaluates whether the required tags are present on EC2 instances, without the need for manual intervention.
upvoted 1 times
...
gulu73
1 year, 2 months ago
Selected Answer: C
C is the answer
upvoted 1 times
...
raychen
2 years, 5 months ago
I will go for A. see the requirement of multiple accounts.
upvoted 1 times
juraj666
2 years, 3 months ago
SCP would enforce the policy, not detect differences in tags, i go with C
upvoted 3 times
...
...
random_007
2 years, 5 months ago
question ask for detection and with least possible overhead. config has capability to check from compliance point view (custom) and which does not require any additional configuration at resource level. Answer : C
upvoted 2 times
...
haim96
2 years, 6 months ago
C. https://aws.amazon.com/blogs/devops/aws-config-checking-for-compliance-with-new-managed-rule-options/
upvoted 1 times
...
sankhar
2 years, 6 months ago
I strong believed that answer is C
upvoted 1 times
...
USR
2 years, 7 months ago
Answer : C
upvoted 3 times
...
qurren
2 years, 7 months ago
I'll go for C
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago