AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company operates separate development and production AWS accounts that are enrolled in AWS Organizations. Security policy states that all new and existing Amazon EBS volumes must be encrypted. The CloudOps team also must email a consolidated CSV report each month that lists every EBS volume that was found non-compliant during that period. Which approach will satisfy both requirements with the least operational overhead?

  • Enable EBS encryption by default in each account with an AWS Config remediation runbook. Rely on this setting to bring all existing volumes into compliance and use configuration snapshots to an S3 bucket as the monthly report.

  • Turn on the Security Hub "EC2.5 EBS encryption" control and configure a Lambda function to act on new findings by encrypting affected volumes; schedule a weekly Security Hub CSV export through QuickSight and email the results.

  • Enable the AWS Config managed rule "ebs-encrypted-volume" in every account. Create an EventBridge rule that targets an SSM Automation runbook to snapshot, encrypt, and replace any NON_COMPLIANT volume. Deploy the same rule in an AWS Config conformance pack, aggregate results in the security account, export the monthly compliance report to an S3 bucket, and notify the security mailbox with Amazon SNS.

  • Use Amazon GuardDuty to detect unencrypted EBS volumes, trigger an AWS Step Functions workflow to encrypt them, and query GuardDuty findings with Athena each month to produce the required CSV report.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot