AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
Your company enabled the managed AWS Config rule s3-bucket-public-read-prohibited. The security team mandates that any noncompliant Amazon S3 bucket automatically blocks all public access within five minutes, and that AWS Config records the remediation. Which solution satisfies these requirements by using only native AWS Config capabilities?
Add the rule to an aggregator, deploy a conformance pack, and rely on pack-level remediation to block public access.
Configure the rule to trigger a Lambda function that removes public ACLs and enable a high-frequency evaluation schedule.
Attach an SSM Automation runbook to the rule and specify the remediation action to invoke AWSConfigRemediation-ConfigureS3BucketPublicAccessBlock using an IAM service role.
Set the rule's ComplianceType to AUTO_REMEDIATE and use an EventBridge rule to call the S3 PutPublicAccessBlock API.
AWS Config supports automatic remediation by attaching an SSM Automation runbook to a rule. For S3 public access findings, the AWS-provided runbook AWSConfigRemediation-ConfigureS3BucketPublicAccessBlock can be selected as the remediation action. When a bucket is flagged NON_COMPLIANT, the runbook is invoked through an IAM service role to enable all four S3 Block Public Access settings. The invocation status is logged by AWS Config, meeting the requirement for recorded remediation within the desired timeframe. The other options either rely on custom Lambda code, reference unsupported rule properties, or use features that do not perform remediation themselves.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SSM Automation runbook in AWS?
Open an interactive chat with Bash
How does AWS Config automatic remediation work?
Open an interactive chat with Bash
What are the S3 Block Public Access settings?
Open an interactive chat with Bash
What is an SSM Automation runbook, and how does it work?
Open an interactive chat with Bash
What are the four S3 Block Public Access settings, and why are they important?
Open an interactive chat with Bash
What role does an IAM service role play in compliance remediation in AWS Config?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .