exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 4 discussion

A SysOps administrator has enabled AWS CloudTrail in an AWS account. If CloudTrail is disabled, it must be re-enabled immediately.
What should the SysOps administrator do to meet these requirements WITHOUT writing custom code?

  • A. Add the AWS account to AWS Organizations. Enable CloudTrail in the management account.
  • B. Create an AWS Config rule that is invoked when CloudTrail configuration changes. Apply the AWS-ConfigureCloudTrailLogging automatic remediation action.
  • C. Create an AWS Config rule that is invoked when CloudTrail configuration changes. Configure the rule to invoke an AWS Lambda function to enable CloudTrail.
  • D. Create an Amazon EventBridge (Amazon CloudWatch Event) hourly rule with a schedule pattern to run an AWS Systems Manager Automation document to enable CloudTrail.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ogum
2 days ago
Selected Answer: B
B. Create an AWS Config rule that is invoked when CloudTrail configuration changes. Apply the AWS-ConfigureCloudTrailLogging automatic remediation action. Most Voted
upvoted 1 times
...
examaws
1 month, 2 weeks ago
Selected Answer: B
Explanation: Option B directly addresses the requirement to re-enable CloudTrail without writing custom code. By using an AWS Config rule with an automatic remediation action, it ensures that CloudTrail is enabled whenever its configuration changes, thus meeting the requirement efficiently. Why not the others? A: Adding the account to AWS Organizations and enabling CloudTrail in the management account does not ensure immediate re-enablement of CloudTrail in the specific account. C: This option involves invoking a Lambda function, which implies writing custom code, contrary to the requirement. D: While using EventBridge could work, it introduces unnecessary complexity and does not directly address the immediate need to re-enable CloudTrail without custom code.
upvoted 1 times
...
64rl0
5 months ago
Selected Answer: B
Answer is B
upvoted 1 times
...
Rabbit117
1 year, 1 month ago
Selected Answer: B
B. Create an AWS Config rule that is invoked when CloudTrail configuration changes. Apply the AWS-ConfigureCloudTrailLogging automatic remediation action.
upvoted 1 times
...
NAVADIYA
1 year, 3 months ago
B. Create an AWS Config rule that is invoked when CloudTrail configuration changes. Apply the AWS-ConfigureCloudTrailLogging automatic remediation action.
upvoted 1 times
...
arana1992
1 year, 3 months ago
B. Create an AWS Config rule that is invoked when CloudTrail configuration changes. Apply the AWS-ConfigureCloudTrailLogging automatic remediation action. Option B allows for automatic remediation of CloudTrail configuration changes. By creating an AWS Config rule with the AWS-ConfigureCloudTrailLogging remediation action, you can ensure that if CloudTrail is ever disabled, it will be automatically re-enabled. Option A (adding the AWS account to AWS Organizations and enabling CloudTrail in the management account) is not directly related to re-enabling CloudTrail if it's disabled. Option C (creating an AWS Config rule to invoke a Lambda function) would require writing custom code, which is specifically mentioned as not being allowed in the question. Option D (creating an Amazon EventBridge rule with an Automation document) would also require custom code through AWS Systems Manager Automation documents, which is not allowed as per the question's constraints.
upvoted 1 times
...
callspace
1 year, 4 months ago
B is correct as question clearly says WITHOUT writing custom code so C can't be correct.
upvoted 1 times
...
marcoeu
1 year, 4 months ago
B ... https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/automatically-re-enable-aws-cloudtrail-by-using-a-custom-remediation-rule-in-aws-config.html
upvoted 1 times
...
bakamon
1 year, 7 months ago
Selected Answer: C
AWS-ConfigureCloudTrailLogging does not exist at all
upvoted 1 times
AgboolaKun
8 months, 3 weeks ago
The answer is B. I did not know that AWS-ConfigureCloudTrailLogging exist in AWS Systems Manager until I checked too. You can find it in Systems Manager -> Documents, then check Automation documents box under Categories session, then you will see "AWS-ConfigureCloudTrailLogging". In fact, if you click on AWS-ConfigureCloudTrailLogging link, you will see a state machine visual that explains how to use this automation.
upvoted 1 times
...
elanelans
1 year, 6 months ago
It does... Login to account > AWS Systems Manager > Documents (Under shared resources) All documents then search for key word "AWS-ConfigureCloudTrailLogging"
upvoted 5 times
...
...
mamila
1 year, 8 months ago
Selected Answer: C
AWS-ConfigureCloudTrailLogging does not exist, a lambda has to be called to enable CloudTrail answer is C.
upvoted 2 times
elanelans
1 year, 6 months ago
It does... Login to account > AWS Systems Manager > Documents (Under shared resources) All documents then search for key word "AWS-ConfigureCloudTrailLogging"
upvoted 3 times
...
...
Gomer
1 year, 9 months ago
I have a hard time voting for "B" just because there is no "AWS-ConfigureCloudTrailLogging" Config rule, SSM Document, SSM Runbook, SSM Automation. There is a SSM "Runbook" named "AWS-EnableCloudTrail" that I presume wold make "D" work, but it seems kludgy to check hourly for something that could be automated to turn on when it's turned off with no wait period. Not sure if this is a trick question or just a poorly worded question. "B" is wrong if you take the wording literally. If you presume they really meant to say was to use "cloudtrail-enabled" config rule, then it might be correct. But that is NOT what it says.
upvoted 2 times
...
CVDON
1 year, 12 months ago
B But i would use SCP to prevent any disabling action. https://aws.amazon.com/es/blogs/industries/best-practices-for-aws-organizations-service-control-policies-in-a-multi-account-environment/
upvoted 2 times
...
michaldavid
2 years, 2 months ago
Selected Answer: B
bbbbbbbbbb
upvoted 1 times
...
Liongeek
2 years, 2 months ago
I agree with you all that B is the answer but that remedation doesn't exist. We'll have to add it from a template and CUSTOMIZE it so ummm....
upvoted 1 times
...
Surferbolt
2 years, 4 months ago
Selected Answer: B
B, Config can check and also remediate automatically.
upvoted 2 times
...
Yoyo76
2 years, 7 months ago
B was my choice
upvoted 1 times
...
ceros399
2 years, 8 months ago
Selected Answer: B
Ans= B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago