Use the drift detection Config rule with an EventBridge rule on NON_COMPLIANT targeting SNS
A company is using AWS CloudFormation to perform deployments of its application environment. A deployment failed during a recent update to the existing CloudFormation stack. A DevOps engineer discovered that some resources in the stack were manually modified. The DevOps engineer needs a solution that detects manual modification of resources and sends an alert to the DevOps lead. Which solution will meet these requirements with the LEAST operational effort?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Every element of the least-effort path is a managed integration: the managed rule detects drift, EventBridge reacts to the NON_COMPLIANT status without a Lambda function in between, and SNS delivers the notification to a subscribed email address (A). Option C matches on COMPLIANT, which is the opposite of the drift condition and would fire constantly rather than on drift. Option B requires writing a custom rule with the RDKlib plus a Lambda function to send email, adding code to maintain. Option D uses the managed rule and EventBridge but inserts a Lambda function solely to send an email that SNS already handles.
Detecting manual modification of CloudFormation-managed resources and alerting the DevOps lead with the least effort means using managed components rather than custom code. The CLOUDFORMATION_STACK_DRIFT_DETECTION_CHECK managed rule reports drift as a non-compliance status, an EventBridge rule can be matched on that NON_COMPLIANT configuration status, and the existing SNS topic with the lead subscribed delivers the alert directly as the rule target.
Creating an EventBridge rule invoked on the COMPLIANT resources status (C) — COMPLIANT is the normal, expected state, so this rule would fire on every successful evaluation rather than on drift, producing constant false alerts instead of detecting manual modification. Using a custom Config rule built with the RDKlib plus a Lambda function to send email (B) — this requires developing, deploying, and maintaining a custom rule and a function, which directly contradicts the least operational effort requirement. Using a Lambda function to send the email (D) — uncledana favored D, but SNS with an email subscription already delivers the notification natively, so a function adds code and cost for no benefit.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Manual modification of CloudFormation-managed resources shows up as drift, and AWS Config provides a managed rule for exactly this, CLOUDFORMATION_STACK_DRIFT_DETECTION_CHECK, which evaluates the stack against its template and reports the result through the configuration item status. When a resource becomes non-compliant, AWS Config emits a configuration compliance change event to EventBridge, so an EventBridge rule matched on that NON_COMPLIANT status can target the existing SNS topic directly. Because the DevOps lead is already subscribed to the topic, the alert is delivered with no Lambda function and no custom code, which is the least operational effort path (A).Why the Other Options Are Wrong
B tags all CloudFormation resources and then requires a custom AWS Config rule developed with the AWS Config Rules Development Kit to check resource changes, plus an EventBridge rule and a Lambda function that sends the email. This is a substantial amount of custom code to develop, deploy, and maintain when a managed rule already performs drift detection out of the box, directly contradicting the least-effort requirement. C uses the same managed rule but configures the EventBridge rule to be invoked on the COMPLIANT resources status. COMPLIANT is the expected steady state of a healthy stack, so this rule would fire on ordinary evaluations rather than on drift, generating a stream of false alerts and failing to identify manual modification. D uses the managed rule and an EventBridge rule on NON_COMPLIANT correctly, but introduces a Lambda function whose only job is to send an email message to the DevOps lead; SNS with an email subscription already does that natively, so the function adds code, cost, and a failure point for no benefit. uncledana preferred D for its component selection, but it is strictly more complex than A. A is the correct answer.Community Comment Notes
Community voted A (91). Srikantha identified the managed rule as the built-in detector of drift on CloudFormation-managed resources. Ky_24 framed the three key requirements and concluded A meets them. luisfsm_111 and Impromptu both argued that the least operational overhead means using managed services rather than writing code, with Impromptu specifically noting that A avoids creating a Lambda function just to send a notification. uncledana favored D, but its Lambda email step duplicates what SNS already does.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →