List of questions
Related questions
Question 493 - DOP-C01 discussion
A company uses federated access for its AWS environment. The company creates and manages IAM roles by using AWS CloudFormation from a CI/CD pipeline. All changes should be made to the IAM roles through the pipeline. The company’s security team discovers that out-of-band changes are being made to the IAM roles. The security team needs a way to detect when these out-of-band changes occur. What should a DevOps engineer do to meet this requirement?
A.
Use Amazon Inspector rules to detect and notify when an AWS CloudFormation stack has a configuration change.
B.
Use AWS Trusted Advisor to detect and notify when an AWS CloudFormation stack has a configuration change.
C.
Use AWS CloudTrail to detect and notify when an AWS CloudFormation stack detects a configuration change.
D.
Use an AWS Config rule to detect and notify when AWS CloudFormation drift detection identifies a configuration change.
Your answer:
0 comments
Sorted by
Leave a comment first