exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 20 discussion

A company uses AWS Organizations to manage a multi-account AWS environment in a single AWS Region. The organization's management account is named management-01. The company has turned on AWS Config in all accounts in the organization. The company has designated an account named security-01 as the delegated administrator for AWS Config.
All accounts report the compliance status of each account's rules to the AWS Config delegated administrator account by using an AWS Config aggregator. Each account administrator can configure and manage the account's own AWS Config rules to handle each account's unique compliance requirements.
A security engineer needs to implement a solution to automatically deploy a set of 10 AWS Config rules to all existing and future AWS accounts in the organization. The solution must turn on AWS Config automatically during account creation.
Which combination of steps will meet these requirements? (Choose two.)

  • A. Create an AWS CloudFormation template that contains the 10 required AWS Config rules. Deploy the template by using CloudFormation StackSets in the security-01 account.
  • B. Create a conformance pack that contains the 10 required AWS Config rules. Deploy the conformance pack from the security-01 account.
  • C. Create a conformance pack that contains the 10 required AWS Config rules. Deploy the conformance pack from the management-01 account.
  • D. Create an AWS CloudFormation template that will activate AWS Config. Deploy the template by using CloudFormation StackSets in the security-01 account.
  • E. Create an AWS CloudFormation template that will activate AWS Config. Deploy the template by using CloudFormation StackSets in the management-01 account.
Show Suggested Answer Hide Answer
Suggested Answer: BE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Christina666
Highly Voted 1 year ago
Selected Answer: BE
Use management account to delegate accounts for auditing, security or compliance, then use delegated account to deploy conformance packs
upvoted 8 times
...
walter_white_008
Most Recent 9 months, 2 weeks ago
why is D not correct ? a delegated admin can deploy the stacks to enable the AWS config and its preferable to use the delegated account over admin account. What am I missing ?
upvoted 1 times
Haykhay
3 weeks, 4 days ago
Delegated admin for AWS config. Not delegated admin for AWS org which manages stackset
upvoted 1 times
...
...
Daibin
11 months, 1 week ago
I'd go with B and E https://aws.amazon.com/blogs/mt/using-delegated-admin-for-aws-config-operations-and-aggregation/
upvoted 3 times
...
trashbox
11 months, 3 weeks ago
Exam on 2023-12-18
upvoted 1 times
...
Raphaello
11 months, 4 weeks ago
"security-01 account" is a delegated administrator account, so let's agree that either Cfn stacksets or Config rules will be deployed from this account. Now, since there are multiple accounts, deploying AWS Config rules (conformance pack) would be through CloudFormation template/stackset. AD seems right choices for me, albeit B is not wrong but it misses the deployment part of Config rules.
upvoted 2 times
Raphaello
9 months, 4 weeks ago
Obviously I was wrong. BE are the best answers.
upvoted 1 times
...
...
Daniel76
1 year ago
Selected Answer: BE
I go with B and E. https://aws.amazon.com/blogs/mt/deploying-conformance-packs-across-an-organization-with-automatic-remediation/ Delegated administrator for AWS Organizations https://docs.aws.amazon.com/organizations/latest/userguide/orgs_delegate_policies.html
upvoted 4 times
...
Aamee
1 year ago
Selected Answer: CE
I'd probably go with C and E since the AWS documentation shows that it's only the management account from where the CFN stack can be deployed at along with the Conformance Packs which can also be deployed at the Management/Master account level. But pls. correct me if I understood it incorrectly somewhere... Thnx!
upvoted 1 times
Josh1217
8 months, 3 weeks ago
https://aws.amazon.com/blogs/mt/deploy-aws-config-rules-and-conformance-packs-using-a-delegated-admin/
upvoted 1 times
...
...
Aamee
1 year ago
https://aws.amazon.com/blogs/mt/deploying-conformance-packs-across-an-organization-with-automatic-remediation/ From the source above, it looks like the Conformance Packs can be setup only by the Master Account (Which probably in this usecase, it's the Management account I guess). "These conformance packs and their underlying config rules and remediations actions are not modifiable by your organization’s member accounts. Only master accounts can create, update, and delete organization conformance packs." Still confused as to why we've the Security-01 account setup as the AWS Config Delegated administrator for all the member accounts?..
upvoted 1 times
...
[Removed]
1 year, 1 month ago
Selected Answer: BE
B and E
upvoted 1 times
...
lalee2
1 year, 1 month ago
Selected Answer: BE
B and E. Conformance should be set up in admin account but in the question it says 'security-01 as the delegated administrator for AWS Config'. I would pick B and E here.
upvoted 3 times
...
pupsik
1 year, 1 month ago
Selected Answer: BE
Agree with @bhui.
upvoted 1 times
...
bhui
1 year, 1 month ago
Selected Answer: BE
Should be BE https://aws.amazon.com/blogs/mt/deploying-conformance-packs-across-an-organization-with-automatic-remediation/ B as security account is the AWS Config delegated admin
upvoted 4 times
bhui
1 year, 1 month ago
Supplementing my thoughts with this blog. https://aws.amazon.com/blogs/mt/org-aggregator-delegated-admin/ 1. To enable AWS Config access to AWS Organizations - Run the following command from your organization management account: 2. To set up an aggregator using delegated admin
upvoted 4 times
...
...
Sumi81
1 year, 1 month ago
CE https://aws.amazon.com/blogs/mt/deploying-conformance-packs-across-an-organization-with-automatic-remediation/
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...