Use the drift detection Config rule with an EventBridge rule on NON_COMPLIANT targeting SNS

Answer Correct answer: A — use the drift detection Config rule with an EventBridge rule on NON_COMPLIANT that targets the SNS topic.

A company is using AWS CloudFormation to perform deployments of its application environment. A deployment failed during a recent update to the existing CloudFormation stack. A DevOps engineer discovered that some resources in the stack were manually modified. The DevOps engineer needs a solution that detects manual modification of resources and sends an alert to the DevOps lead. Which solution will meet these requirements with the LEAST operational effort?

  1. Create an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the DevOps lead to the topic by using an email address. Create an AWS Config managed rule that has the CLOUDFORMATION_STACK_DRIFT_DETECTION_CHECK identifier. Create an Amazon EventBridge rule that is invoked on the NON_COMPLIANT resources status. Set the SNS topic as the rule target. Correct Answer
  2. Tag all CloudFormation resources with a specific tag. Create an AWS Config custom rule by using the AWS Config Rules Development Kit Library (RDKlib) that checks all resource changes that have the specific tag. Configure the custom rule to mark all the tagged resource changes as NON_COMPLIANT when the change is not performed by CloudFormation. Create an Amazon EventBridge rule that is invoked on the NON_COMPUANT resources status. Create an AWS Lambda function that sends an email message to the DevOps lead. Set the Lambda function as the rule target.
  3. Create an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the DevOps lead to the topic by using an email address. Create an AWS Config managed rule that has the CLOUDFORMATION_STACK_DRIFT_DETECTION_CHECK identifier. Create an Amazon EventBridge rule that is invoked on the COMPLIANT resources status. Set the SNS topic as the rule target.
  4. Create an AWS Config managed rule that has the CLOUDFORMATION_STACK_DRIFT_DETECTION_CHECK identifier. Create an Amazon EventBridge rule that is invoked on the NON_COMPLIANT resources status. Create an AWS Lambda function that sends an email message to the DevOps lead. Set the Lambda function as the rule target.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Every element of the least-effort path is a managed integration: the managed rule detects drift, EventBridge reacts to the NON_COMPLIANT status without a Lambda function in between, and SNS delivers the notification to a subscribed email address (A). Option C matches on COMPLIANT, which is the opposite of the drift condition and would fire constantly rather than on drift. Option B requires writing a custom rule with the RDKlib plus a Lambda function to send email, adding code to maintain. Option D uses the managed rule and EventBridge but inserts a Lambda function solely to send an email that SNS already handles.

Detecting manual modification of CloudFormation-managed resources and alerting the DevOps lead with the least effort means using managed components rather than custom code. The CLOUDFORMATION_STACK_DRIFT_DETECTION_CHECK managed rule reports drift as a non-compliance status, an EventBridge rule can be matched on that NON_COMPLIANT configuration status, and the existing SNS topic with the lead subscribed delivers the alert directly as the rule target.

Creating an EventBridge rule invoked on the COMPLIANT resources status (C) — COMPLIANT is the normal, expected state, so this rule would fire on every successful evaluation rather than on drift, producing constant false alerts instead of detecting manual modification. Using a custom Config rule built with the RDKlib plus a Lambda function to send email (B) — this requires developing, deploying, and maintaining a custom rule and a function, which directly contradicts the least operational effort requirement. Using a Lambda function to send the email (D) — uncledana favored D, but SNS with an email subscription already delivers the notification natively, so a function adds code and cost for no benefit.

Community Discussion (5 comments)

Srikantha 👍 1 Selected: A
AWS Config Managed Rule (CLOUDFORMATION_STACK_DRIFT_DETECTION_CHECK): The CLOUDFORMATION_STACK_DRIFT_DETECTION_CHECK is a built-in AWS Config rule that automatically detects drift on resources managed by CloudFormation. Drift refers to manual changes made to CloudFormation-managed resources, and this rule identifies such changes. EventBridge Rule: You can create an EventBridge rule that listens for NON_COMPLIANT events triggered by the AWS Config rule when drift is detected. This will ensure that whenever there are manual modifications on CloudFormation-managed resources, the event will be captured. SNS Notification: Using Amazon SNS, you can set up an email notification for the DevOps lead whenever the event is triggered. Subscribing the DevOps lead to the SNS topic ensures that they are immediately notified without requiring manual intervention.
Ky_24 👍 3 Selected: A
Key Requirements: 1. Detect manual modification of CloudFormation-managed resources. 2. Send an alert to the DevOps lead when such changes are detected. 3. Achieve this with minimal operational effort.
luisfsm_111 👍 3 Selected: A
Least operational overhead always will involve using AWS-Managed services instead of developing code, for example. So, A in my opinion.
Impromptu 👍 3 Selected: A
A is less complex by just using SNS for notifying, instead of creating a lambda function just to do that.
uncledana 👍 1 Selected: D
Option D is the most efficient and least operationally complex solution because it uses AWS Config’s drift detection rule, integrates with EventBridge for event handling, and leverages a Lambda function to send notifications. This approach directly addresses the need to detect manual changes in CloudFormation-managed resources and alert the DevOps lead.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Manual modification of CloudFormation-managed resources shows up as drift, and AWS Config provides a managed rule for exactly this, CLOUDFORMATION_STACK_DRIFT_DETECTION_CHECK, which evaluates the stack against its template and reports the result through the configuration item status. When a resource becomes non-compliant, AWS Config emits a configuration compliance change event to EventBridge, so an EventBridge rule matched on that NON_COMPLIANT status can target the existing SNS topic directly. Because the DevOps lead is already subscribed to the topic, the alert is delivered with no Lambda function and no custom code, which is the least operational effort path (A).

Why the Other Options Are Wrong

B tags all CloudFormation resources and then requires a custom AWS Config rule developed with the AWS Config Rules Development Kit to check resource changes, plus an EventBridge rule and a Lambda function that sends the email. This is a substantial amount of custom code to develop, deploy, and maintain when a managed rule already performs drift detection out of the box, directly contradicting the least-effort requirement. C uses the same managed rule but configures the EventBridge rule to be invoked on the COMPLIANT resources status. COMPLIANT is the expected steady state of a healthy stack, so this rule would fire on ordinary evaluations rather than on drift, generating a stream of false alerts and failing to identify manual modification. D uses the managed rule and an EventBridge rule on NON_COMPLIANT correctly, but introduces a Lambda function whose only job is to send an email message to the DevOps lead; SNS with an email subscription already does that natively, so the function adds code, cost, and a failure point for no benefit. uncledana preferred D for its component selection, but it is strictly more complex than A. A is the correct answer.

Community Comment Notes

Community voted A (91). Srikantha identified the managed rule as the built-in detector of drift on CloudFormation-managed resources. Ky_24 framed the three key requirements and concluded A meets them. luisfsm_111 and Impromptu both argued that the least operational overhead means using managed services rather than writing code, with Impromptu specifically noting that A avoids creating a Lambda function just to send a notification. uncledana favored D, but its Lambda email step duplicates what SNS already does.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide