exam questions

Exam AWS Certified DevOps Engineer - Professional DOP-C02 All Questions

View all questions & answers for the AWS Certified DevOps Engineer - Professional DOP-C02 exam

Exam AWS Certified DevOps Engineer - Professional DOP-C02 topic 1 question 198 discussion

A company uses Amazon RDS for all databases in its AWS accounts. The company uses AWS Control Tower to build a landing zone that has an audit and logging account. All databases must be encrypted at rest for compliance reasons. The company's security engineer needs to receive notification about any noncompliant databases that are in the company’s accounts.

Which solution will meet these requirements with the MOST operational efficiency?

  • A. Use AWS Control Tower to activate the optional detective control (guardrail) to determine whether the RDS storage is encrypted. Create an Amazon Simple Notification Service (Amazon SNS) topic in the company's audit account. Create an Amazon EventBridge rule to filter noncompliant events from the AWS Control Tower control (guardrail) to notify the SNS topic. Subscribe the security engineer's email address to the SNS topic.
  • B. Use AWS CloudFormation StackSets to deploy AWS Lambda functions to every account. Write the Lambda function code to determine whether the RDS storage is encrypted in the account the function is deployed to. Send the findings as an Amazon CloudWatch metric to the management account. Create an Amazon Simple Notification Service (Amazon SNS) topic. Create a CloudWatch alarm that notifies the SNS topic when metric thresholds are met. Subscribe the security engineer's email address to the SNS topic.
  • C. Create a custom AWS Config rule in every account to determine whether the RDS storage is encrypted. Create an Amazon Simple Notification Service (Amazon SNS) topic in the audit account. Create an Amazon EventBidge rule to filter noncompliant events from the AWS Control Tower control (guardrail) to notify the SNS topic. Subscribe the security engineer's email address to the SNS topic.
  • D. Launch an Amazon C2 instance. Run an hourly cron job by using the AWS CLI to determine whether the RDS storage is encrypted in each AWS account. Store the results in an RDS database. Notify the security engineer by sending email messages from the EC2 instance when noncompliance is detected
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jamesf
9 months ago
Selected Answer: A
Keywords: Control Tower A company uses Amazon RDS for all databases in its AWS accounts. The company uses AWS Control Tower
upvoted 2 times
...
didek1986
1 year ago
Selected Answer: A
A https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#disallow-rds-storage-unencrypted
upvoted 3 times
...
dkp
1 year ago
Selected Answer: A
most efficient way is A
upvoted 3 times
...
DanShone
1 year, 1 month ago
Selected Answer: A
A - least operational overhead
upvoted 3 times
...
sejar
1 year, 1 month ago
Selected Answer: C
Guardrail uses AWS Config for compliance detection
upvoted 3 times
...
Diego1414
1 year, 2 months ago
Selected Answer: C
Answer: C - https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#disallow-rds-storage-unencrypted
upvoted 2 times
...
thanhnv142
1 year, 2 months ago
Selected Answer: A
A is correct: we need guardraild to detect non-compliances B and D: no mention of guardrail. C: Though this option mentions guardrail, it uses AWS Config to detect non-compliances
upvoted 4 times
thanhnv142
1 year, 2 months ago
correction: C
upvoted 1 times
...
...
Ramdi1
1 year, 2 months ago
Selected Answer: A
Leverages existing infrastructure: It utilizes native AWS Control Tower functionality for compliance checks and integrates seamlessly with SNS for notifications. Centralized management: Configuration and monitoring are done in the audit account, eliminating the need for individual resources in each account. Scalability: Handles future account growth without manual intervention.
upvoted 4 times
...
vortegon
1 year, 2 months ago
Selected Answer: A
https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#disallow-rds-storage-unencrypted
upvoted 4 times
...
Arnaud92
1 year, 2 months ago
Selected Answer: A
https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#disallow-rds-storage-unencrypted
upvoted 3 times
...
hotblooded
1 year, 2 months ago
Selected Answer: C
Compliance == Aws config
upvoted 2 times
Slays
4 months ago
The key here is most operational efficiency. Option C says create a rule in every account. Control tower is more efficient in this regard.
upvoted 1 times
...
Chelseajcole
1 year, 2 months ago
thanks for the summary
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago