Activate the Control Tower RDS encryption guardrail and notify through EventBridge to SNS

Answer Correct answer: A — activate the Control Tower RDS encryption control and use EventBridge to route noncompliant events to an SNS topic for notification.

A company uses Amazon RDS for all databases in its AWS accounts. The company uses AWS Control Tower to build a landing zone that has an audit and logging account. All databases must be encrypted at rest for compliance reasons. The company's security engineer needs to receive notification about any noncompliant databases that are in the company’s accounts. Which solution will meet these requirements with the MOST operational efficiency?

  1. Use AWS Control Tower to activate the optional detective control (guardrail) to determine whether the RDS storage is encrypted. Create an Amazon Simple Notification Service (Amazon SNS) topic in the company's audit account. Create an Amazon EventBridge rule to filter noncompliant events from the AWS Control Tower control (guardrail) to notify the SNS topic. Subscribe the security engineer's email address to the SNS topic. Correct Answer
  2. Use AWS CloudFormation StackSets to deploy AWS Lambda functions to every account. Write the Lambda function code to determine whether the RDS storage is encrypted in the account the function is deployed to. Send the findings as an Amazon CloudWatch metric to the management account. Create an Amazon Simple Notification Service (Amazon SNS) topic. Create a CloudWatch alarm that notifies the SNS topic when metric thresholds are met. Subscribe the security engineer's email address to the SNS topic.
  3. Create a custom AWS Config rule in every account to determine whether the RDS storage is encrypted. Create an Amazon Simple Notification Service (Amazon SNS) topic in the audit account. Create an Amazon EventBidge rule to filter noncompliant events from the AWS Control Tower control (guardrail) to notify the SNS topic. Subscribe the security engineer's email address to the SNS topic.
  4. Launch an Amazon C2 instance. Run an hourly cron job by using the AWS CLI to determine whether the RDS storage is encrypted in each AWS account. Store the results in an RDS database. Notify the security engineer by sending email messages from the EC2 instance when noncompliance is detected

Community Votes

A
78%
C
22%

78% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Control Tower already exists in this organization, so activating its pre-built RDS-encryption control and wiring the resulting Config noncompliance events to SNS through EventBridge adds essentially no operational overhead (A). Writing a custom Config rule in every account (C) or deploying scheduled Lambda functions via StackSets (B) distributes custom code and maintenance across all accounts, and an hourly EC2 cron job (D) is the least efficient of all.

With AWS Control Tower already governing the landing zone and all databases running on Amazon RDS, the most operationally efficient compliance path is to activate the built-in optional control that detects unencrypted RDS storage and create an EventBridge rule that routes its noncompliant events to an SNS topic the security engineer subscribes to. No per-account custom code or scheduled jobs are needed.

Writing a custom AWS Config rule in every account (C)—although the guardrail itself is implemented with AWS Config, building and distributing a custom rule to every account adds overhead that Control Tower's pre-built control avoids. Deploying Lambda functions to every account through StackSets to poll encryption state (B)—this is custom code operating on a schedule rather than an event-driven compliance signal, so it is far less efficient.

Community Discussion (11 comments)

jamesf 👍 2 Selected: A
Keywords: Control Tower A company uses Amazon RDS for all databases in its AWS accounts. The company uses AWS Control Tower
didek1986 👍 3 Selected: A
A https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#disallow-rds-storage-unencrypted
dkp 👍 3 Selected: A
most efficient way is A
DanShone 👍 3 Selected: A
A - least operational overhead
sejar 👍 3 Selected: C
Guardrail uses AWS Config for compliance detection
Diego1414 👍 2 Selected: C
Answer: C - https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#disallow-rds-storage-unencrypted
thanhnv142 👍 4 Selected: A
A is correct: we need guardraild to detect non-compliances B and D: no mention of guardrail. C: Though this option mentions guardrail, it uses AWS Config to detect non-compliances
Ramdi1 👍 3 Selected: A
Leverages existing infrastructure: It utilizes native AWS Control Tower functionality for compliance checks and integrates seamlessly with SNS for notifications. Centralized management: Configuration and monitoring are done in the audit account, eliminating the need for individual resources in each account. Scalability: Handles future account growth without manual intervention.
vortegon 👍 4 Selected: A
https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#disallow-rds-storage-unencrypted
Arnaud92 👍 3 Selected: A
https://docs.aws.amazon.com/controltower/latest/userguide/strongly-recommended-controls.html#disallow-rds-storage-unencrypted
hotblooded 👍 2 Selected: C
Compliance == Aws config

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The landing zone is already governed by AWS Control Tower with a dedicated audit and logging account, so the built-in control that detects whether RDS storage is encrypted can simply be activated and its findings consumed as events. Creating an EventBridge rule that filters those noncompliance events and targets an SNS topic, then subscribing the security engineer's email, delivers the required notification with no code deployed to member accounts and no polling—this is the most operationally efficient option given Control Tower is already in place.

Why the Other Options Are Wrong

B deploys Lambda functions into every account via StackSets that query encryption state on a schedule and publish custom metrics, adding code distribution and maintenance. C creates a custom Config rule in every account, which duplicates a capability Control Tower already provides as a ready control and requires rolling the rule out org-wide. D launches an EC2 instance running an hourly cron job and emails directly, which is the least automated and least reliable option. A is the most efficient.

Community Comment Notes

Community voted A (78), with C a minority (22). Commenters keyed on the phrase 'the company uses AWS Control Tower', noting that A leverages an existing Control Tower control with the least operational overhead. One commenter noted that guardrails use AWS Config underneath, which is true but does not change that A avoids deploying any custom rule or code to member accounts.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide