AWS Certified Solutions Architect Professional SAP-C02 Practice Question

Your company operates more than 400 AWS member accounts that are centrally managed with AWS Organizations. The security team needs to be alerted whenever any Amazon S3 bucket in a member account receives a resource-based policy that makes the bucket publicly readable or grants read access to principals outside the organization. Notifications must arrive within 1 hour of the policy change and be delivered to an existing Amazon SNS topic in the security-tooling account. The team also wants a single console where they can review all historical findings. The solution must introduce the least ongoing operational overhead.

Which combination of actions will meet these requirements?

  • In every member account, enable the AWS Config managed rule s3-bucket-public-read-prohibited, aggregate the rule results to a central aggregator in the security-tooling account, and configure an EventBridge rule that forwards NON_COMPLIANT events to the SNS topic.

  • Enable Amazon GuardDuty S3 protection for the organization and configure GuardDuty findings to be forwarded through AWS Security Hub to the SNS topic.

  • Register the security-tooling account as the delegated administrator for IAM Access Analyzer, create an organization-level external-access analyzer there, and add an Amazon EventBridge rule that sends new aws.access-analyzer finding events to the existing SNS topic.

  • Enable Amazon Macie organization-wide from the management account and create EventBridge rules in the security-tooling account that forward Macie Policy:IAMUser/S3BucketPublic findings to the SNS topic.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot