Question 1 of 30
A company has implemented AWS Config to monitor its AWS resources for compliance with internal security policies. They have set up a rule that checks whether all EC2 instances are tagged with a specific key-value pair. After a recent audit, the security team found that several EC2 instances were non-compliant with this tagging requirement. To address this issue, the team decides to create a remediation action that automatically adds the required tags to any non-compliant EC2 instances. Which of the following steps should the team take to ensure that the remediation action is effective and adheres to best practices in AWS Config?
Create an AWS Lambda function that triggers on AWS Config rule compliance changes and uses the AWS SDK to add the required tags to non-compliant instances.
Manually tag the non-compliant instances using the AWS Management Console to ensure compliance with the tagging policy.
Set up an AWS CloudTrail event to log all changes made to EC2 instances and review them periodically for compliance.
Use AWS Systems Manager to run a script that checks for compliance and tags instances as needed on a scheduled basis.

Preparing for Amazon SCS-C02 AWS Certified Security – Specialty (SCS-C02)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free