ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 115 - 312-40 discussion

Report
Export

Kenneth Danziger has been working as a cloud security engineer in a multinational company. His organization uses AWS cloud-based services. Kenneth would like to review the changes in configuration and the relationships between AWS resources, examine the detailed resource configuration history, and determine the overall compliance of his organization against the configurations specified in internal guidelines. Which of the following AWS services enables Kenneth to assess, audit, and evaluate the configuration of AWS resources?

A.
AWS CloudTrail
Answers
A.
AWS CloudTrail
B.
AWS CloudFormation
Answers
B.
AWS CloudFormation
C.
AWS Config
Answers
C.
AWS Config
D.
AWS Security Hub
Answers
D.
AWS Security Hub
Suggested answer: C

Explanation:

AWS Config is the service that enables Kenneth to assess, audit, and evaluate the configurations of AWS resources.

1.AWS Config: This service provides a detailed view of the configuration of AWS resources within the account. It includes a history of configuration changes and relationships between AWS resources, making it possible to review changes and determine overall compliance against internal guidelines1.

1.Capabilities of AWS Config:

oConfiguration and Relationship Review: AWS Config records and evaluates the configurations and relationships of AWS resources, allowing Kenneth to track changes and review the environment's compliance status.

oResource Configuration History: It maintains a detailed history of the configurations of AWS resources over time.

oCompliance Evaluation: AWS Config can assess resource configurations against desired configurations to ensure compliance with internal guidelines.

1.Why Not the Others?:

oAWS CloudTrail: This service is focused on providing event history of your AWS account activity, including actions taken through the AWS Management Console, AWS SDKs, command line tools, and other AWS services.

oAWS CloudFormation: While CloudFormation is used for creating and managing a collection of related AWS resources, it does not provide configuration history or compliance evaluation.

oAWS Security Hub: Security Hub gives a comprehensive view of high-priority security alerts and compliance status across AWS accounts, but it does not offer detailed configuration history or relationship tracking.

AWS Config: Assess, audit, and evaluate configurations of your resources1.

asked 18/09/2024
Shrini Ch
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first