ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 493 - DOP-C01 discussion

Report
Export

A company uses federated access for its AWS environment. The company creates and manages IAM roles by using AWS CloudFormation from a CI/CD pipeline. All changes should be made to the IAM roles through the pipeline. The company’s security team discovers that out-of-band changes are being made to the IAM roles. The security team needs a way to detect when these out-of-band changes occur. What should a DevOps engineer do to meet this requirement?

A.
Use Amazon Inspector rules to detect and notify when an AWS CloudFormation stack has a configuration change.
Answers
A.
Use Amazon Inspector rules to detect and notify when an AWS CloudFormation stack has a configuration change.
B.
Use AWS Trusted Advisor to detect and notify when an AWS CloudFormation stack has a configuration change.
Answers
B.
Use AWS Trusted Advisor to detect and notify when an AWS CloudFormation stack has a configuration change.
C.
Use AWS CloudTrail to detect and notify when an AWS CloudFormation stack detects a configuration change.
Answers
C.
Use AWS CloudTrail to detect and notify when an AWS CloudFormation stack detects a configuration change.
D.
Use an AWS Config rule to detect and notify when AWS CloudFormation drift detection identifies a configuration change.
Answers
D.
Use an AWS Config rule to detect and notify when AWS CloudFormation drift detection identifies a configuration change.
Suggested answer: C

Explanation:

Reference: https://aws.amazon.com/blogs/mt/how-to-track-configuration-changes-to-cloudformation-stacks-using-awsconfig/

asked 16/09/2024
Kinzonji Tavares
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first