Activate the Control Tower RDS encryption guardrail and notify through EventBridge to SNS
A company uses Amazon RDS for all databases in its AWS accounts. The company uses AWS Control Tower to build a landing zone that has an audit and logging account. All databases must be encrypted at rest for compliance reasons. The company's security engineer needs to receive notification about any noncompliant databases that are in the company’s accounts. Which solution will meet these requirements with the MOST operational efficiency?
Community Votes
78% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Control Tower already exists in this organization, so activating its pre-built RDS-encryption control and wiring the resulting Config noncompliance events to SNS through EventBridge adds essentially no operational overhead (A). Writing a custom Config rule in every account (C) or deploying scheduled Lambda functions via StackSets (B) distributes custom code and maintenance across all accounts, and an hourly EC2 cron job (D) is the least efficient of all.
With AWS Control Tower already governing the landing zone and all databases running on Amazon RDS, the most operationally efficient compliance path is to activate the built-in optional control that detects unencrypted RDS storage and create an EventBridge rule that routes its noncompliant events to an SNS topic the security engineer subscribes to. No per-account custom code or scheduled jobs are needed.
Writing a custom AWS Config rule in every account (C)—although the guardrail itself is implemented with AWS Config, building and distributing a custom rule to every account adds overhead that Control Tower's pre-built control avoids. Deploying Lambda functions to every account through StackSets to poll encryption state (B)—this is custom code operating on a schedule rather than an event-driven compliance signal, so it is far less efficient.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The landing zone is already governed by AWS Control Tower with a dedicated audit and logging account, so the built-in control that detects whether RDS storage is encrypted can simply be activated and its findings consumed as events. Creating an EventBridge rule that filters those noncompliance events and targets an SNS topic, then subscribing the security engineer's email, delivers the required notification with no code deployed to member accounts and no polling—this is the most operationally efficient option given Control Tower is already in place.Why the Other Options Are Wrong
B deploys Lambda functions into every account via StackSets that query encryption state on a schedule and publish custom metrics, adding code distribution and maintenance. C creates a custom Config rule in every account, which duplicates a capability Control Tower already provides as a ready control and requires rolling the rule out org-wide. D launches an EC2 instance running an hourly cron job and emails directly, which is the least automated and least reliable option. A is the most efficient.Community Comment Notes
Community voted A (78), with C a minority (22). Commenters keyed on the phrase 'the company uses AWS Control Tower', noting that A leverages an existing Control Tower control with the least operational overhead. One commenter noted that guardrails use AWS Config underneath, which is true but does not change that A avoids deploying any custom rule or code to member accounts.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →