Use AWS Config remediation with EBS encryption by default to fix and prevent unencrypted volumes
A company has deployed applications to thousands of Amazon EC2 instances in an AWS account. A security audit discovers that several unencrypted Amazon Elastic Block Store (Amazon EBS) volumes are attached to the EC2 instances. The company’s security policy requires the EBS volumes to be encrypted. The company needs to implement an automated solution to encrypt the EBS volumes. The solution also must prevent development teams from creating unencrypted EBS volumes. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The two requirements are solved by two different mechanisms: AWS Config with a remediation runbook handles the existing unencrypted volumes automatically, while the EBS encryption by default account setting makes every new volume encrypted at creation time.
A security audit found unencrypted EBS volumes attached to thousands of EC2 instances, and policy requires all of them to be encrypted. The company needs both an automated way to encrypt the existing volumes and a preventive control so development teams cannot create new unencrypted volumes.
Trying to enforce encryption with a key policy deny statement or an SCP. A deny on the KMS key does not block the CreateVolume call itself, and an SCP denying unencrypted volume creation is written around a condition that is evaluated at a different point, whereas the account setting applies encryption before the volume exists.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The AWS Config managed rule for unencrypted EBS volumes continuously detects the existing unencrypted volumes, and configuring an automatic remediation action that invokes a Systems Manager Automation runbook encrypts them without manual intervention, which satisfies the first requirement at scale across thousands of instances. Modifying the account setting so that EBS encryption is always enabled for new volumes makes encryption the default at creation, so development teams can no longer produce unencrypted volumes even if they do not specify encryption, which satisfies the preventive requirement with no policy work per team.Why the Other Options Are Wrong
A: A deny statement in a KMS key policy cannot prevent creation of an unencrypted volume, because an unencrypted volume does not use the key, and there is nothing in the key policy to deny at CreateVolume time. B and C: Systems Manager Fleet Manager can list instances but it is not a detection-and-remediation control for unencrypted volumes the way a Config managed rule with automatic remediation is, and neither option includes a preventive control. C in particular omits any prevention step, so development teams could immediately create new unencrypted volumes. D is the only option that pairs proactive remediation with the preventive account setting.Community Comment Notes
The community voted 90 to 1 for D. Commenters pointed to the AWS prescriptive guidance pattern for automatically encrypting existing and new EBS volumes and confirmed the account setting, rather than an SCP or key policy, is what makes new volumes encrypted by default. The single dissenting vote for B correctly noted that Fleet Manager alone remediates but does not prevent.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →