exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 457 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 457
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company has a requirement that none of its Amazon RDS resources can be publicly accessible. A security engineer needs to set up monitoring for this requirement and must receive a near-real-time notification if any RDS resource is noncompliant.

Which combination of steps should the security engineer take to meet these requirements? (Choose three.)

  • A. Configure RDS event notifications on each RDS resource. Target an AWS Lambda function that notifies AWS Config of a change to the RDS public access setting
  • B. Configure the rds-instance-public-access-check AWS Config managed rule to monitor the RDS resources.
  • C. Configure the Amazon EventBridge (Amazon CloudWatch Events) rule to target an Amazon Simple Notification Service (Amazon SNS) topic to provide a notification to the security engineer.
  • D. Configure RDS event notifications to post events to an Amazon Simple Queue Service (Amazon SQS) queue. Subscribe the SQS queue to an Amazon Simple Notification Service (Amazon SNS) topic to provide a notification to the security engineer.
  • E. Configure an Amazon EventBridge (Amazon CloudWatch Events) rule that is invoked by a compliance change event from the rds-instance-public-access-check rule.
  • F. Configure an Amazon EventBridge (Amazon CloudWatch Events) rule that is invoked when the AWS Lambda function notifies AWS Config of an RDS event change.
Show Suggested Answer Hide Answer
Suggested Answer: BCE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AdamWest
Highly Voted 2 years, 5 months ago
Selected Answer: BCE
BCE - 100% https://docs.aws.amazon.com/config/latest/developerguide/rds-instance-public-access-check.html
upvoted 6 times
...
Singhh
Highly Voted 2 years, 5 months ago
Selected Answer: BCE
ConfigRuleName: "rds-instance-public-access-check" >> Amazon EventBridge (Amazon CloudWatch Events) >> Amazon Simple Notification Service (Amazon SNS)
upvoted 5 times
...
kujin
Most Recent 2 years, 1 month ago
ACE - rds-instance-public-access-check rule cannot be monitored by AWS Config in near real time hence, B and E is incorrect. A can detect the configuration change in near real time by the Lambda, F can generate EventBridge event and C can notify to security engineer. The Lambda notifying to AWS Config is irrelevant to the requirement.
upvoted 1 times
kujin
2 years, 1 month ago
Sorry A->F->C
upvoted 2 times
...
...
maddyr
2 years, 5 months ago
Selected Answer: BCE
BCE is correct
upvoted 3 times
...
D2
2 years, 5 months ago
Selected Answer: BCE
Answer BEC
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago