AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An AWS CloudOps engineer must ensure that any Amazon S3 bucket that appears in the Trusted Advisor security check "Amazon S3 Bucket Permissions" with a status of Action recommended is immediately remediated. The remediation must remove any public read ACLs, enable Block Public Access on the bucket, and send an email notification to the security team. Which approach meets these requirements with the least operational overhead?

  • Create an EventBridge rule that matches Trusted Advisor Check Item Change events for the S3 bucket permissions check and a status of Action recommended; set the target to a Lambda function that removes the public ACL, enables Block Public Access, and publishes a message to an SNS topic.

  • Add an S3 ObjectCreated event notification on every bucket that triggers a Lambda function to revoke public ACLs, enable Block Public Access, and email the security team after each daily Trusted Advisor refresh.

  • Configure an Amazon GuardDuty finding-based EventBridge rule that invokes a Systems Manager Run Command document to set the bucket ACL to private and email the security team.

  • Enable the AWS Config managed rule s3-bucket-public-read-prohibited and configure automatic remediation with a Systems Manager Automation document that changes the ACL and sends an SNS notification.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot