ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 109 - SOA-C02 discussion

Report
Export

A large company is using AWS Organizations to manage hundreds of AWS accounts across multiple AWS Regions. The company has turned on AWS Config throughout the organization. The company requires all Amazon S3 buckets to block public read access. A SysOps administrator must generate a monthly report that shows all the S3 buckets and whether they comply with this requirement. Which combination of steps should the SysOps administrator take to collect this data? (Choose two.)

A.
Create an AWS Config aggregator in an aggregator account. Use the organization as the source. Retrieve the compliance data from the aggregator.
Answers
A.
Create an AWS Config aggregator in an aggregator account. Use the organization as the source. Retrieve the compliance data from the aggregator.
B.
Create an AWS Config aggregator in each account. Use an S3 bucket in an aggregator account as the destination. Retrieve the compliance data from the S3 bucket.
Answers
B.
Create an AWS Config aggregator in each account. Use an S3 bucket in an aggregator account as the destination. Retrieve the compliance data from the S3 bucket.
C.
Edit the AWS Config policy in AWS Organizations. Use the organization's management account to turn on the S3-bucketpublic- read-prohibited rule for the entire organization.
Answers
C.
Edit the AWS Config policy in AWS Organizations. Use the organization's management account to turn on the S3-bucketpublic- read-prohibited rule for the entire organization.
D.
Use the AWS Config compliance report from the organization's management account. Filter the results by resource, and select Amazon S3.
Answers
D.
Use the AWS Config compliance report from the organization's management account. Filter the results by resource, and select Amazon S3.
E.
Use the Aws Config API to apply the s3-bucket-public-read-prohibited rule in all accounts for all available Regions.
Answers
E.
Use the Aws Config API to apply the s3-bucket-public-read-prohibited rule in all accounts for all available Regions.
Suggested answer: B, D

Explanation:

Reference: https://docs.aws.amazon.com/config/latest/developerguide/aggregate-data.html

https://docs.aws.amazon.com/config/latest/developerguide/looking-up-discovered-resources.html

asked 16/09/2024
Tomas Ojeda
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first