nerdexam
Amazon

SCS-C02 · Question #119

A company uses infrastructure as code (IaC) to create AWS infrastructure. The company writes the code as AWS CloudFormation templates to deploy the infrastructure. The company has an existing CI/CD pi

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #119. The question stem and answer options stay visible for context.

Submitted by yuki_2020· Mar 6, 2026Infrastructure Security

Question

A company uses infrastructure as code (IaC) to create AWS infrastructure. The company writes the code as AWS CloudFormation templates to deploy the infrastructure. The company has an existing CI/CD pipeline that the company can use to deploy these templates. After a recent security audit, the company decides to adopt a policy-as-code approach to improve the company's security posture on AWS. The company must prevent the deployment of any infrastructure that would violate a security policy, such as an unencrypted Amazon Elastic Block Store (Amazon EBS) volume. Which solution will meet these requirements?

Options

  • ATurn on AWS Trusted Advisor. Configure security notifications as webhooks in the preferences
  • BTurn on AWS Config. Use the prebuilt rules or customized rules. Subscribe tile CI/CD pipeline to
  • CCreate rule sets in AWS CloudFormation Guard. Run validation checks for CloudFormation
  • DCreate rule sets as SCPs. Integrate the SCPs as a part of validation control in a phase of the

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Policy as Code#CloudFormation Guard#CI/CD Security#Infrastructure as Code (IaC)
Full SCS-C02 Practice