Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 166 discussion

A security administrator has enabled AWS Security Hub for all the AWS accounts in an organization in AWS Organizations. The security team wants near-real-time response and remediation for deployed AWS resources that do not meet security standards. All changes must be centrally logged for auditing purposes.

The organization has reached the quotas for the number of SCPs attached to an OU and SCP document size. The team wants to avoid making any changes to any of the SCPs. The solution must maximize scalability and cost-effectiveness.

Which combination of actions should the security administrator take to meet these requirements? (Choose three.)

  • A. Create an AWS Config custom rule to detect configuration changes to AWS resources. Create an AWS Lambda function to remediate the AWS resources in the delegated administrator AWS account.
  • B. Use AWS Systems Manager Change Manager to track configuration changes to AWS resources. Create a Systems Manager document to remediate the AWS resources in the delegated administrator AWS account.
  • C. Create a Security Hub custom action to reference in an Amazon EventBridge event rule in the delegated administrator AWS account.
  • D. Create an Amazon EventBridge event rule to Invoke an AWS Lambda function that will take action on AWS resources.
  • E. Create an Amazon EventBridge event rule to invoke an AWS Lambda function that will evaluate AWS resource configuration for a set of API requests and create a finding for noncompllant AWS resources.
  • F. Create an Amazon EventBridge event rule to invoke an AWS Lambda function on a schedule to assess specific AWS Config rules.
Show Suggested Answer Hide Answer
Suggested Answer: ABE 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
adit
Highly Voted 2 months, 1 week ago
Selected Answer: ACD
acd are correct answer
upvoted 7 times
...
aescudero51
Highly Voted 3 months, 2 weeks ago
Selected Answer: ADE
My answer is A. Create an AWS Config custom rule to detect configuration changes to AWS resources. Create an AWS Lambda function to remediate the AWS resources in the delegated administrator AWS account. My answer is D. Create an Amazon EventBridge event rule to Invoke an AWS Lambda function that will take action on AWS resources. My answer is E. Create an Amazon EventBridge event rule to invoke an AWS Lambda function that will evaluate AWS resource configuration for a set of API requests and create a finding for noncompllant AWS resources.
upvoted 5 times
...
VerRi
Most Recent 2 weeks, 6 days ago
Selected Answer: ACD
I will go for ACD
upvoted 3 times
...
nischal77777
1 month ago
Selected Answer: ADE
ADE is most correct answer
upvoted 1 times
...
sema2232
2 months, 3 weeks ago
CDE are correct answers
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...