ANS-C01 · Question #132
A company recently implemented a security policy that prohibits developers from launching VPC network infrastructure. The policy states that any time a NAT gateway is launched in a VPC, the…
The correct answer is D. Create a custom AWS Config rule that checks for NAT gateways in an AWS account. Configure. https://docs.aws.amazon.com/config/latest/developerguide/view-compliance-history.html https://aws.amazon.com/blogs/mt/remediate-noncompliant-aws-config-rules-with-aws-systems- manager-automation-runbooks/
Question
A company recently implemented a security policy that prohibits developers from launching VPC network infrastructure. The policy states that any time a NAT gateway is launched in a VPC, the company's network security team must immediately receive an alert to terminate the NAT gateway. The network security team needs to implement a solution that can be deployed across AWS accounts with the least possible administrative overhead. The solution also must provide the network security team with a simple way to view compliance history. Which solution will meet these requirements?
Options
- ADevelop a script that programmatically checks for NAT gateways in an AWS account, sends an
- BCreate an AWS Lambda function that programmatically checks for NAT gateways in an AWS
- CEnable Amazon GuardDuty. Create an Amazon EventBridge rule for the
- DCreate a custom AWS Config rule that checks for NAT gateways in an AWS account. Configure
How the community answered
(30 responses)- A20% (6)
- B13% (4)
- C7% (2)
- D60% (18)
Explanation
https://docs.aws.amazon.com/config/latest/developerguide/view-compliance-history.html https://aws.amazon.com/blogs/mt/remediate-noncompliant-aws-config-rules-with-aws-systems- manager-automation-runbooks/
Topics
Community Discussion
No community discussion yet for this question.