exam questions

Exam AWS Certified SAP on AWS - Specialty PAS-C01 All Questions

View all questions & answers for the AWS Certified SAP on AWS - Specialty PAS-C01 exam

Exam AWS Certified SAP on AWS - Specialty PAS-C01 topic 1 question 31 discussion

A company is running its SAP workload on AWS. The company’s security team has implemented the following requirements:
All Amazon EC2 instances for SAP must be SAP certified instance types.
Encryption must be enabled for all Amazon S3 buckets and Amazon Elastic Block Store (Amazon EBS) volumes.
AWS CloudTrail must be activated.
SAP system parameters must be compliant with business rules.
Detailed monitoring must be enabled for all instances.
The company wants to develop an automated process to review the systems for compliance with the security team’s requirements. The process also must provide notification about any deviation from these standards.
Which solution will meet these requirements?

  • A. Use AWS AppConfig to model configuration data in an AWS Systems Manager Automation runbook. Schedule this Systems Manager Automation runbook to monitor for compliance with all the requirements. Integrate AWS AppConfig with Amazon CloudWatch for notification purposes.
  • B. Use AWS Config managed rules to monitor for compliance with all the requirements. Use Amazon EventBridge (Amazon CloudWatch Events) and Amazon Simple Notification Service (Amazon SNS) for email notification when a resource is flagged as noncompliant.
  • C. Use AWS Trusted Advisor to monitor for compliance with all the requirements. Use Trusted Advisor preferences for email notification when a resource is flagged as noncompliant.
  • D. Use AWS Config managed rules to monitor for compliance with the requirements, except for the SAP system parameters. Create AWS Config custom rules to validate the SAP system parameters. Use Amazon EventBridge (Amazon CloudWatch Events) and Amazon Simple Notification Service (Amazon SNS) for email notification when a resource is flagged as noncompliant.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kaishin0527
1 year, 9 months ago
Selected Answer: D
D: AWS Config managed rules can monitor AWS resources for compliance with specified configurations. However, AWS Config does not have built-in functionality to monitor SAP system parameters, so you would need to create custom rules for this purpose. AWS Config can then use Amazon EventBridge (formerly known as Amazon CloudWatch Events) to trigger notifications via Amazon SNS when a resource is found to be noncompliant. This solution provides the needed automation and compliance review capabilities.
upvoted 1 times
...
[Removed]
1 year, 10 months ago
Selected Answer: D
Obvious D,
upvoted 1 times
...
easytoo
1 year, 11 months ago
d-d-d-d-d-d
upvoted 2 times
...
schalke04
2 years, 3 months ago
Selected Answer: D
D looks good
upvoted 4 times
...
Kiran1982
2 years, 3 months ago
Selected Answer: D
https://aws.amazon.com/blogs/awsforsap/audit-your-sap-systems-with-aws-config-part-ii/
upvoted 4 times
...
forexamweb
2 years, 3 months ago
Selected Answer: D
D https://aws.amazon.com/blogs/awsforsap/audit-your-sap-systems-with-aws-config-part-i/ https://aws.amazon.com/blogs/awsforsap/audit-your-sap-systems-with-aws-config-part-ii/
upvoted 1 times
...
kk8s
2 years, 3 months ago
Selected Answer: B
B for me. https://aws.amazon.com/blogs/awsforsap/audit-your-sap-systems-with-aws-config-part-i/
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago