Q232.A company with multiple accounts is currently using a configuration that does not meet the following security governance policies:Prevent ingress from port 22 to any Amazon EC2 instance .Require billing and application tag

欢迎免费使用小程序搜题/刷题/查看解析,提升学历,成考自考报名,论文代写、论文查重请加客服微信skr-web


Q232.A company with multiple accounts is currently using a configuration that does not meet the following security governance policies:Prevent ingress from port 22 to any Amazon EC2 instance .Require billing and application tags for resources.Encrypt all Amazon EBS volumes.A Solutions Architect wants to
Provide preventive and detective controls including notifications about a specific resource if there are policy deviations.Which solution should the Solutions Architect implement?

A.Create an AWS CodeCommit repository containing policy-compliant AWS CloudFormation templates.Create an AWS Service Catalog portfolio. Import the CloudFormation templates by attaching the CodeCommit repository to the portfolio.Restrict users across all accounts to items from the AWS Service Catalog portfolio. Use AWS Config managed rules to detect deviations from the policies. Configure an Amazon CloudWatch Events rule for deviations and associate a CloudWatch alarm to send notifications when the TriggeredRules metric is greater than zero .
B.Use AWS Service Catalog to build a portfolio with products that are in compliance with the governance policies in a central account. Restrict users across all accounts to AWS Service Catalog products. Share a compliant portfolio to other accounts. Use AWS Config managed rules to detect deviations from the policies. Configure an Amazon CloudWatch Events rule to send a notification when a deviation occurs.
C.Implement policy-compliant AWS CloudFormation templates for each account and ensure that all provisioning is completed by CloudFormation. Configure Amazon Inspector to perform regular checks against resources. Perform policy validation and write the assessment output to Amazon CloudWatch Logs. Create a CloudWatch Logs metric filter to increment a metric when a deviation occurs.
Configure a CloudWatch alarm to send notifications when the configured metric is greater than zero. D.Restrict users and enforce least privilege access using AWS IAM. Consolidate all AWS CloudTrail logs into a single account. Send the CloudTrail logs to Amazon Elasticsearch Service (Amazon ES). Implement monitoring alerting and reporting using the Kibana dashboard in Amazon ES and with Amazon SNS.
正确答案B
访客
邮箱
网址

通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作


  • 自动写文案
  • 自动写小说
  • 马上扫码让Ai帮你完成工作
通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作

  • 自动写论文
  • 自动写软件
  • 我不是人,但是我比人更聪明,我是强大的Ai
Top