Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 318 discussion

A company recently migrated its entire IT environment to the AWS Cloud. The company discovers that users are provisioning oversized Amazon EC2 instances and modifying security group rules without using the appropriate change control process. A solutions architect must devise a strategy to track and audit these inventory and configuration changes.

Which actions should the solutions architect take to meet these requirements? (Choose two.)

  • A. Enable AWS CloudTrail and use it for auditing.
  • B. Use data lifecycle policies for the Amazon EC2 instances.
  • C. Enable AWS Trusted Advisor and reference the security dashboard.
  • D. Enable AWS Config and create rules for auditing and compliance purposes.
  • E. Restore previous resource configurations with an AWS CloudFormation template.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
LuckyAro
Highly Voted 1 year, 6 months ago
Selected Answer: AD
A. Enable AWS CloudTrail and use it for auditing. CloudTrail provides event history of your AWS account activity, including actions taken through the AWS Management Console, AWS Command Line Interface (CLI), and AWS SDKs and APIs. By enabling CloudTrail, the company can track user activity and changes to AWS resources, and monitor compliance with internal policies and external regulations. D. Enable AWS Config and create rules for auditing and compliance purposes. AWS Config provides a detailed inventory of the AWS resources in your account, and continuously records changes to the configurations of those resources. By creating rules in AWS Config, the company can automate the evaluation of resource configurations against desired state, and receive alerts when configurations drift from compliance. Options B, C, and E are not directly relevant to the requirement of tracking and auditing inventory and configuration changes.
upvoted 12 times
...
Ruffyit
Most Recent 10 months, 1 week ago
A. Enable AWS CloudTrail and use it for auditing. CloudTrail provides event history of your AWS account activity, including actions taken through the AWS Management Console, AWS Command Line Interface (CLI), and AWS SDKs and APIs. By enabling CloudTrail, the company can track user activity and changes to AWS resources, and monitor compliance with internal policies and external regulations. D. Enable AWS Config and create rules for auditing and compliance purposes. AWS Config provides a detailed inventory of the AWS resources in your account, and continuously records changes to the configurations of those resources. By creating rules in AWS Config, the company can automate the evaluation of resource configurations against desired state, and receive alerts when configurations drift from compliance. Options B, C, and E are not directly relevant to the requirement of tracking and auditing inventory and configuration changes.
upvoted 1 times
...
Guru4Cloud
1 year ago
Selected Answer: AD
A. Enable AWS CloudTrail and use it for auditing. CloudTrail provides event history of your AWS account activity, including actions taken through the AWS Management Console, AWS Command Line Interface (CLI), and AWS SDKs and APIs. By enabling CloudTrail, the company can track user activity and changes to AWS resources, and monitor compliance with internal policies and external regulations. D. Enable AWS Config and create rules for auditing and compliance purposes. AWS Config provides a detailed inventory of the AWS resources in your account, and continuously records changes to the configurations of those resources. By creating rules in AWS Config, the company can automate the evaluation of resource configurations against desired state, and receive alerts when configurations drift from compliance.
upvoted 1 times
...
mrsoa
1 year, 1 month ago
Selected Answer: CD
I am gonna go with CD AWS Cloudtrail is already enabled so no need to enable it and for the auding we are gonna use AWS config Answer D C because Trusted advisor checks the security groups
upvoted 1 times
awsgeek75
8 months ago
CloudTrail is not enabled by default or in the question scenario. Even if it was, Trusted Advisor would just give you recommendations and usage reports. It won't audit anything for you
upvoted 1 times
...
pentium75
8 months, 3 weeks ago
"AWS CloudTrail is already enabled" says who?
upvoted 2 times
...
...
kruasan
1 year, 4 months ago
Selected Answer: AD
A) Enable AWS CloudTrail and use it for auditing. AWS CloudTrail provides a record of API calls and can be used to audit changes made to EC2 instances and security groups. By analyzing CloudTrail logs, the solutions architect can track who provisioned oversized instances or modified security groups without proper approval. D) Enable AWS Config and create rules for auditing and compliance purposes. AWS Config can record the configuration changes made to resources like EC2 instances and security groups. The solutions architect can create AWS Config rules to monitor for non-compliant changes, like launching certain instance types or opening security group ports without permission. AWS Config would alert on any violations of these rules.
upvoted 2 times
kruasan
1 year, 4 months ago
The other options would not fully meet the auditing and change tracking requirements: B) Data lifecycle policies control when EC2 instances are backed up or deleted but do not audit configuration changes. C) AWS Trusted Advisor security checks may detect some compliance violations after the fact but do not comprehensively log changes like AWS CloudTrail and AWS Config do. E) CloudFormation templates enable rollback but do not provide an audit trail of changes. The solutions architect would not know who made unauthorized modifications in the first place.
upvoted 2 times
...
...
skiwili
1 year, 7 months ago
Selected Answer: AD
Yes A and D
upvoted 1 times
...
jennyka76
1 year, 7 months ago
AGREE WITH ANSWER - A & D CloudTrail and Config
upvoted 1 times
...
Neha999
1 year, 7 months ago
CloudTrail and Config
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...