SCS-C02 · Question #119
A company uses infrastructure as code (IaC) to create AWS infrastructure. The company writes the code as AWS CloudFormation templates to deploy the infrastructure. The company has an existing CI/CD pi
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #119. The question stem and answer options stay visible for context.
Question
A company uses infrastructure as code (IaC) to create AWS infrastructure. The company writes the code as AWS CloudFormation templates to deploy the infrastructure. The company has an existing CI/CD pipeline that the company can use to deploy these templates. After a recent security audit, the company decides to adopt a policy-as-code approach to improve the company's security posture on AWS. The company must prevent the deployment of any infrastructure that would violate a security policy, such as an unencrypted Amazon Elastic Block Store (Amazon EBS) volume. Which solution will meet these requirements?
Options
- ATurn on AWS Trusted Advisor. Configure security notifications as webhooks in the preferences
- BTurn on AWS Config. Use the prebuilt rules or customized rules. Subscribe tile CI/CD pipeline to
- CCreate rule sets in AWS CloudFormation Guard. Run validation checks for CloudFormation
- DCreate rule sets as SCPs. Integrate the SCPs as a part of validation control in a phase of the
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.