AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A security engineer must ensure that every internet-facing Application Load Balancer (ALB) and Amazon CloudFront distribution in a single AWS account is protected by an AWS WAF v2 web ACL. The engineer wants to receive automatic non-compliance findings without writing custom code. Which solution will provide the required visibility with the least operational overhead?
Turn on AWS CloudTrail Lake and create a query that searches for CreateLoadBalancer and CreateDistribution events without an accompanying CreateWebACLAssociation event.
Deploy an AWS Lambda function triggered by EventBridge events for every new or modified ALB or CloudFront distribution and inspect the resource configuration for the WebAclId field.
Enable the AWS Config managed rules alb-waf-enabled and cloudfront-associated-with-waf.
Stream AWS WAF logs to Amazon S3 through Kinesis Data Firehose and use Amazon Athena to run a scheduled query that lists resources without matching web ACL IDs.
AWS Config provides managed rules that continuously evaluate resource configurations. The managed rules alb-waf-enabled and cloudfront-associated-with-waf check whether ALBs and CloudFront distributions are associated with an AWS WAF v2 web ACL. Enabling these two rules covers all requested resource types and automatically generates non-compliant findings when a resource lacks WAF protection, eliminating the need to develop and maintain custom code. The other options either require building additional components or lack complete coverage.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Config and how does it help monitor compliance?
Open an interactive chat with Bash
What is an AWS WAF v2 web ACL and why is it important?
Open an interactive chat with Bash
How do AWS Config managed rules for ALBs and CloudFront distributions work?
Open an interactive chat with Bash
What is AWS Config and how does it help with compliance?
Open an interactive chat with Bash
What is an AWS WAF v2 web ACL and why is it important?
Open an interactive chat with Bash
How do AWS Config managed rules alb-waf-enabled and cloudfront-associated-with-waf work?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .