Enable the AWS Config drift-detection managed rule and alert on its compliance-change event via EventBridge

Answer Correct answer: D — enable the cloudformation-stack-drift-detection-check Config rule and notify SNS from an EventBridge rule on its compliance change event.

A DevOps engineer has developed an AWS Lambda function. The Lambda function starts an AWS CloudFormation drift detection operation on all supported resources for a specific CloudFormation stack. The Lambda function then exits its invocation. The DevOps engineer has created an Amazon EventBridge scheduled rule that invokes the Lambda function every hour. An Amazon Simple Notification Service (Amazon SNS) topic already exists in the AWS account. The DevOps engineer has subscribed to the SNS topic to receive notifications. The DevOps engineer needs to receive a notification as soon as possible when drift is detected in this specific stack configuration. Which solution will meet these requirements?

  1. Configure the existing EventBridge rule to also target the SNS topic. Configure an SNS subscription filter policy to match the CloudFormation stack. Attach the subscription filter policy to the SNS topic.
  2. Create a second Lambda function to query the CloudFormation API for the drift detection results for the stack. Configure the second Lambda function to publish a message to the SNS topic if drift is detected. Adjust the existing EventBridge rule to also target the second Lambda function.
  3. Configure Amazon GuardDuty in the account with drift detection for all CloudFormation stacks. Create a second EventBridge rule that reacts to the GuardDuty drift detection event finding for the specific CloudFormation stack. Configure the SNS topic as a target of the second EventBridge rule.
  4. Configure AWS Config in the account. Use the cloudformation-stack-drift-detection-check managed rule. Create a second EventBridge rule that reacts to a compliance change event for the CloudFormation stack. Configure the SNS topic as a target of the second EventBridge rule. Correct Answer

Community Votes

D
76%
B
24%

76% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

AWS Config's cloudformation-stack-drift-detection-check performs continuous drift detection and emits a configuration compliance change event, which EventBridge can match and forward straight to SNS, giving immediate notification without custom code (D). Option B adds a second Lambda that polls the CloudFormation API, but it would still only run on the hourly schedule, so it cannot deliver 'as soon as possible'. GuardDuty (C) has no CloudFormation stack drift detection capability, and filtering the existing hourly EventBridge rule by stack (A) still leaves detection gated by the hourly cadence.

The existing design starts a CloudFormation drift detection operation every hour, which at best notifies on an hourly cadence and requires extra code to correlate results. To be alerted as soon as drift is detected in the specific stack, enable the AWS Config managed rule cloudformation-stack-drift-detection-check and create a second EventBridge rule that reacts to the configuration compliance change event for that stack, targeting the existing SNS topic so the subscribed engineer is notified immediately.

Adding a second Lambda that queries the CloudFormation API for drift results and publishes to SNS (B)—because that Lambda is still triggered by the hourly EventBridge rule, notifications are still delayed by up to an hour, defeating the 'as soon as possible' requirement. Trying to make GuardDuty detect CloudFormation drift (C)—GuardDuty does not monitor configuration drift of CloudFormation stacks. Adding an SNS filter policy to the existing hourly rule (A)—filtering by stack narrows which messages are delivered but does not make detection more frequent.

Community Discussion (14 comments)

Nano803 👍 7 Selected: D
I recommend checking out this blog which utilizes AWS Config and discusses Edenbridge. Here is the link: https://aws.amazon.com/blogs/mt/implementing-an-alarm-to-automatically-detect-drift-in-aws-cloudformation-stacks/"
kyuhuck 👍 5 Selected: D
Given the options and the requirement for immediate notification upon drift detection, Option D is the most appropriate solution. It leverages AWS Config to continuously monitor and evaluate the configurations of AWS resources, including CloudFormation stacks. When AWS Config detects a drift from the desired configuration, it can trigger an EventBridge rule, which in turn can notify the interested parties via the SNS topic. This approach does not require additional custom logic to check for drift results, as AWS Config handles the evaluation and notification process based on configuration changes.
iulian0585 👍 3 Selected: B
The solution that will meet the requirements of receiving a notification as soon as possible when drift is detected in the specific CloudFormation stack configuration is: B. Create a second Lambda function to query the CloudFormation API for the drift detection results for the stack. Configure the second Lambda function to publish a message to the SNS topic if drift is detected. Adjust the existing EventBridge rule to also target the second Lambda function. Option D (Using AWS Config) would introduce additional complexity and potential delays, as AWS Config periodically evaluates resource configurations and may not provide immediate notifications upon drift detection. By creating a separate Lambda function dedicated to monitoring drift detection results and publishing notifications to the existing SNS topic, you can ensure timely and reliable notifications while maintaining a modular and scalable architecture.
dkp 👍 4 Selected: D
answer D AWS Config Integration: AWS Config is specifically designed to monitor and detect configuration changes and drifts in AWS resources, including CloudFormation stacks. Using AWS Config's built-in cloudformation-stack-drift-detection-check managed rule ensures comprehensive and reliable drift detection for CloudFormation stacks. Event-Driven Architecture: Creating an EventBridge rule that reacts to a compliance change event for the CloudFormation stack allows you to trigger an alert as soon as drift is detected. This event-driven approach ensures timely detection and alerting for CloudFormation stack drift. SNS Notification: By configuring the SNS topic as a target of the EventBridge rule, you can easily send notifications/alerts to various endpoints, including email, SMS, or other AWS services, ensuring immediate alerting when drift is detected.
WhyIronMan 👍 4 Selected: D
D, Use the cloudformation-stack-drift-detection-check managed rule B uses scheduled rule will not notify as soon as possible as it runs hourly
DanShone 👍 5 Selected: D
D woudl be suitable - https://docs.aws.amazon.com/config/latest/developerguide/cloudformation-stack-drift-detection-check.html B would not work as it would still only be triggered once per hour as is using the same event bridge rule
Shasha1 👍 2
D refer this: https://docs.aws.amazon.com/config/latest/developerguide/cloudformation-stack-drift-detection-check.html
dzn 👍 1 Selected: B
The minimum interval for the cloudformation-stack-drift-detection-check managed rule in AWS config is 1 hour and does not meet the following requirements. as soon as possible when drift is detected
fdoxxx 👍 2 Selected: B
B is a suitable solution for meeting the requirements: This solution provides a more direct and responsive approach. The other options involve additional services like GuardDuty (Option C), which is not designed for CloudFormation drift detection, or AWS Config with managed rules (Option D), which may introduce unnecessary complexity for this specific scenario. Option A doesn't provide a straightforward way to react to drift detection events.
Ramdi1 👍 1 Selected: A
Leverages existing infrastructure: This approach utilizes the existing EventBridge rule and SNS topic, avoiding the need for additional resources or complex configurations. Immediate notification: Since the EventBridge rule already triggers the Lambda function every hour, adding the SNS topic as a target ensures drift detection results are published directly to the topic for immediate notification. Filtering for specific stack: Implementing an SNS subscription filter policy ensures you only receive notifications for the specific CloudFormation stack you're interested in, avoiding irrelevant noise.
thanhnv142 👍 1 Selected: B
B: is correct A: SNS topic would be trigger consistenly by the existing evenbridge, so this is incorrect C: Guarduty is for threat detection, not this D: irrelevant, the question requires using ACF drif detection, not AWS config for drift detection
Chelseajcole 👍 2
D. AWS Config
Arnaud92 👍 2 Selected: B
B is the most appropriate solution for this scenario. A is incorrect because although it involves configuring the existing EventBridge rule to target the SNS topic and using an SNS subscription filter policy, it does not involve querying the CloudFormation API for drift detection results. C is incorrect because it involves using Amazon GuardDuty, which is not specifically designed for CloudFormation drift detection. D is incorrect because although it involves using AWS Config and EventBridge to react to compliance change events, it does not directly address CloudFormation drift detection. With CloudWatch Events (now a part of EventBridge) https://aws.amazon.com/fr/blogs/mt/implement-automatic-drift-remediation-for-aws-cloudformation-using-amazon-cloudwatch-and-aws-lambda/
Spavanko 👍 4 Selected: D
B is wrong, you can not query the CloudFormation API

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Config includes a managed rule, cloudformation-stack-drift-detection-check, that continuously compares the actual configuration of a CloudFormation stack against its template and records the result as a configuration item. When the compliance state changes, AWS Config emits a configuration compliance change event to EventBridge. Creating an EventBridge rule scoped to that event for the specific stack and targeting the existing SNS topic delivers the notification to the subscribed engineer as soon as the drift is detected, satisfying the as-soon-as-possible requirement with no custom code.

Why the Other Options Are Wrong

B adds a second Lambda that queries the CloudFormation API for drift results, but that function would be invoked by the existing hourly EventBridge rule, so notifications would still lag by up to an hour; an additional polling function also adds code to maintain. C proposes configuring GuardDuty for drift detection, but GuardDuty is a threat detection service and does not perform CloudFormation configuration drift detection. A adds an SNS subscription filter policy to the existing rule so only messages for the stack are delivered, which reduces noise but leaves detection frequency at the hourly cadence. D is correct.

Community Comment Notes

Community voted D (74), with B a minority (23). Commenters linked the AWS blog on implementing an alarm to automatically detect CloudFormation drift using AWS Config. WhyIronMan noted the decisive point that B still runs on the hourly schedule and therefore cannot notify as soon as possible, while D reacts to an event emitted at detection time.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide