ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 60 - SAP-C02 discussion

Report
Export

A company has an organization in AWS Organizations. The company is using AWS Control Tower to deploy a landing zone for the organization. The company wants to implement governance and policy enforcement. The company must implement a policy that will detect Amazon RDS DB instances that are not encrypted at rest in the company's production OU.

Which solution will meet this requirement?

A.
Turn on mandatory guardrails in AWS Control Tower. Apply the mandatory guardrails to the production OU.
Answers
A.
Turn on mandatory guardrails in AWS Control Tower. Apply the mandatory guardrails to the production OU.
B.
Enable the appropriate guardrail from the list of strongly recommended guardrails in AWS Control Tower. Apply the guardrail to the production OU.
Answers
B.
Enable the appropriate guardrail from the list of strongly recommended guardrails in AWS Control Tower. Apply the guardrail to the production OU.
C.
Use AWS Config to create a new mandatory guardrail. Apply the rule to all accounts in the production OU.
Answers
C.
Use AWS Config to create a new mandatory guardrail. Apply the rule to all accounts in the production OU.
D.
Create a custom SCP in AWS Control Tower. Apply the SCP to the production OU.
Answers
D.
Create a custom SCP in AWS Control Tower. Apply the SCP to the production OU.
Suggested answer: B

Explanation:

AWS Control Tower provides a set of 'strongly recommended guardrails' that can be enabled to implement governance and policy enforcement. One of these guardrails is 'Encrypt Amazon RDS instances' which will detect RDS DB instances that are not encrypted at rest. By enabling this guardrail and applying it to the production OU, the company will be able to enforce encryption for RDS instances in the production environment.

asked 16/09/2024
Ricardson Albuquerque
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first