Enable the AWS Config drift-detection managed rule and alert on its compliance-change event via EventBridge
A DevOps engineer has developed an AWS Lambda function. The Lambda function starts an AWS CloudFormation drift detection operation on all supported resources for a specific CloudFormation stack. The Lambda function then exits its invocation. The DevOps engineer has created an Amazon EventBridge scheduled rule that invokes the Lambda function every hour. An Amazon Simple Notification Service (Amazon SNS) topic already exists in the AWS account. The DevOps engineer has subscribed to the SNS topic to receive notifications. The DevOps engineer needs to receive a notification as soon as possible when drift is detected in this specific stack configuration. Which solution will meet these requirements?
Community Votes
76% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
AWS Config's cloudformation-stack-drift-detection-check performs continuous drift detection and emits a configuration compliance change event, which EventBridge can match and forward straight to SNS, giving immediate notification without custom code (D). Option B adds a second Lambda that polls the CloudFormation API, but it would still only run on the hourly schedule, so it cannot deliver 'as soon as possible'. GuardDuty (C) has no CloudFormation stack drift detection capability, and filtering the existing hourly EventBridge rule by stack (A) still leaves detection gated by the hourly cadence.
The existing design starts a CloudFormation drift detection operation every hour, which at best notifies on an hourly cadence and requires extra code to correlate results. To be alerted as soon as drift is detected in the specific stack, enable the AWS Config managed rule cloudformation-stack-drift-detection-check and create a second EventBridge rule that reacts to the configuration compliance change event for that stack, targeting the existing SNS topic so the subscribed engineer is notified immediately.
Adding a second Lambda that queries the CloudFormation API for drift results and publishes to SNS (B)—because that Lambda is still triggered by the hourly EventBridge rule, notifications are still delayed by up to an hour, defeating the 'as soon as possible' requirement. Trying to make GuardDuty detect CloudFormation drift (C)—GuardDuty does not monitor configuration drift of CloudFormation stacks. Adding an SNS filter policy to the existing hourly rule (A)—filtering by stack narrows which messages are delivered but does not make detection more frequent.
Community Discussion (14 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS Config includes a managed rule, cloudformation-stack-drift-detection-check, that continuously compares the actual configuration of a CloudFormation stack against its template and records the result as a configuration item. When the compliance state changes, AWS Config emits a configuration compliance change event to EventBridge. Creating an EventBridge rule scoped to that event for the specific stack and targeting the existing SNS topic delivers the notification to the subscribed engineer as soon as the drift is detected, satisfying the as-soon-as-possible requirement with no custom code.Why the Other Options Are Wrong
B adds a second Lambda that queries the CloudFormation API for drift results, but that function would be invoked by the existing hourly EventBridge rule, so notifications would still lag by up to an hour; an additional polling function also adds code to maintain. C proposes configuring GuardDuty for drift detection, but GuardDuty is a threat detection service and does not perform CloudFormation configuration drift detection. A adds an SNS subscription filter policy to the existing rule so only messages for the stack are delivered, which reduces noise but leaves detection frequency at the hourly cadence. D is correct.Community Comment Notes
Community voted D (74), with B a minority (23). Commenters linked the AWS blog on implementing an alarm to automatically detect CloudFormation drift using AWS Config. WhyIronMan noted the decisive point that B still runs on the hourly schedule and therefore cannot notify as soon as possible, while D reacts to an event emitted at detection time.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →
cloudformation-stack-drift-detection-checkmanaged rule in AWS config is 1 hour and does not meet the following requirements.as soon as possible when drift is detected