Question 1 of 30
A company has implemented AWS Config to monitor the configuration history of its resources. They want to ensure compliance with their internal security policies and need to analyze the configuration changes over the past 30 days. The security team is particularly interested in identifying any unauthorized changes to security groups and IAM roles. What is the best approach for the security team to achieve this analysis effectively?
Utilize AWS Config's configuration history feature to review the changes made to security groups and IAM roles over the last 30 days, and set up AWS Config rules to alert on any non-compliant changes.
Manually check the AWS Management Console for each security group and IAM role to identify changes made in the last 30 days.
Use AWS CloudTrail logs to filter for events related to security groups and IAM roles, and analyze the logs for unauthorized changes.
Implement a third-party monitoring tool to track changes to security groups and IAM roles without using AWS Config.

Preparing for Amazon SCS-C02 AWS Certified Security – Specialty (SCS-C02)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free