ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 215 - SCS-C01 discussion

Report
Export

A company’s security policy requires that VPC Flow Logs are enabled on all VPCs. A Security Engineer is looking to automate the process of auditing the VPC resources for compliance. What combination of actions should the Engineer take? (Choose two.)

A.
Create an AWS Lambda function that determines whether Flow Logs are enabled for a given VPC.
Answers
A.
Create an AWS Lambda function that determines whether Flow Logs are enabled for a given VPC.
B.
Create an AWS Config configuration item for each VPC in the company AWS account.
Answers
B.
Create an AWS Config configuration item for each VPC in the company AWS account.
C.
Create an AWS Config managed rule with a resource type of AWS:: Lambda:: Function.
Answers
C.
Create an AWS Config managed rule with a resource type of AWS:: Lambda:: Function.
D.
Create an Amazon CloudWatch Event rule that triggers on events emitted by AWS Config.
Answers
D.
Create an Amazon CloudWatch Event rule that triggers on events emitted by AWS Config.
E.
Create an AWS Config custom rule, and associate it with an AWS Lambda function that contains the evaluating logic.
Answers
E.
Create an AWS Config custom rule, and associate it with an AWS Lambda function that contains the evaluating logic.
Suggested answer: A, E

Explanation:

https://medium.com/mudita-misra/how-to-audit-your-aws-resources-for-security-compliance-byusing-custom-aws-config-rules-2e53b09006de

asked 16/09/2024
Aamir Muhammad
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first