DOP-C02 · Question #114
A company is using AWS Organizations to centrally manage its AWS accounts. The company has turned on AWS Config in each member account by using AWS CloudFormation StackSets. The company has…
The correct answer is D. Create an AWS Config conformance pack that contains the AWS Config rules and remediation. https://aws.amazon.com/blogs/mt/deploying-conformance-packs-across-an-organization-with- automatic-remediation/
Question
A company is using AWS Organizations to centrally manage its AWS accounts. The company has turned on AWS Config in each member account by using AWS CloudFormation StackSets. The company has configured trusted access in Organizations for AWS Config and has configured a member account as a delegated administrator account for AWS Config. A DevOps engineer needs to implement a new security policy. The policy must require all current and future AWS member accounts to use a common baseline of AWS Config rules that contain remediation actions that are managed from a central account. Non-administrator users who can access member accounts must not be able to modify this common baseline of AWS Config rules that are deployed into each member account. Which solution will meet these requirements?
Options
- ACreate a CloudFormation template that contains the AWS Config rules and remediation actions.
- BCreate an AWS Config conformance pack that contains the AWS Config rules and remediation
- CCreate a CloudFormation template that contains the AWS Config rules and remediation actions.
- DCreate an AWS Config conformance pack that contains the AWS Config rules and remediation
How the community answered
(26 responses)- A8% (2)
- B12% (3)
- C23% (6)
- D58% (15)
Explanation
https://aws.amazon.com/blogs/mt/deploying-conformance-packs-across-an-organization-with- automatic-remediation/
Topics
Community Discussion
No community discussion yet for this question.