Question 1 of 30
A company has implemented AWS Config to monitor the configuration history of its resources. They want to ensure compliance with their internal security policies by reviewing changes made to their security groups over the past 30 days. The security team is particularly interested in identifying any unauthorized changes that could lead to potential vulnerabilities. Given that AWS Config records configuration changes and stores them in an S3 bucket, what is the most effective way for the security team to analyze the configuration history and identify unauthorized changes?
Utilize AWS Config's built-in query capabilities to filter and analyze the configuration history of security groups directly from the AWS Management Console.
Manually download the configuration history files from the S3 bucket and analyze them using a local script.
Set up a CloudWatch alarm to notify the team of any changes to security groups without analyzing the history.
Use AWS CloudTrail to review API calls related to security group modifications and correlate them with the configuration history.

Preparing for Amazon SCS-C02 AWS Certified Security – Specialty (SCS-C02)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free