exam questions

Exam AWS DevOps Engineer Professional All Questions

View all questions & answers for the AWS DevOps Engineer Professional exam

Exam AWS DevOps Engineer Professional topic 1 question 101 discussion

Exam question from Amazon's AWS DevOps Engineer Professional
Question #: 101
Topic #: 1
[All AWS DevOps Engineer Professional Questions]

A company uses Amazon S3 to store proprietary information. The development team creates buckets for new projects on a daily basis. The security team wants to ensure that all existing and future buckets have encryption, logging, and versioning enabled. Additionally, no buckets should ever be publicly read or write accessible.

What should a DevOps engineer do to meet these requirements?

  • A. Enable AWS CloudTrail and configure automatic remediation using AWS Lambda.
  • B. Enable AWS Config rules and configure automatic remediation using AWS Systems Manager documents.
  • C. Enable AWS Trusted Advisor and configure automatic remediation using Amazon CloudWatch Events.
  • D. Enable AWS Systems Manager and configure automatic remediation using Systems Manager documents.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SatenderRathee
Highly Voted 2 years, 5 months ago
Selected Answer: B
B. Enable AWS Config rules and configure automatic remediation using AWS Systems Manager documents. To meet the requirements specified in the question, the DevOps engineer should enable AWS Config rules and use AWS Systems Manager documents to automate the process of ensuring that all existing and future Amazon S3 buckets have encryption, logging, and versioning enabled, and that no buckets are publicly readable or writable. AWS Config rules allow the security team to specify rules for how resources should be configured in their AWS environment, and AWS Systems Manager documents can be used to automate the process of remedying any non-compliant resources.
upvoted 5 times
...
easytoo
Most Recent 2 years, 1 month ago
b-b-b-b-b-b-b- By using AWS Config rules, the DevOps engineer can ensure that all existing and future S3 buckets have encryption, logging, and versioning enabled. The DevOps engineer can then use AWS Systems Manager documents to automatically remediate any noncompliant resources, ensuring that all S3 buckets remain secure.
upvoted 2 times
...
bgc1
2 years, 2 months ago
Selected Answer: B
https://docs.aws.amazon.com/config/latest/developerguide/remediation.html
upvoted 1 times
...
Piccaso
2 years, 3 months ago
Selected Answer: B
A : CloudTrail+Lambda is .... B : Looks nice C : .... D : ....
upvoted 1 times
...
Bulti
2 years, 3 months ago
Selected Answer: B
Answer is B
upvoted 1 times
...
Imstack
2 years, 4 months ago
BBBBBBBBBBBBBB
upvoted 1 times
...
SmileyCloud
2 years, 5 months ago
Selected Answer: B
B - correct. Anytime there is something regarding compliance and enforcement, your best bet is AWS Config.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago