Use AWS Config remediation with EBS encryption by default to fix and prevent unencrypted volumes

Answer Correct answer: D — Use a Config managed rule with automatic remediation to encrypt existing volumes and set EBS encryption by default for new volumes.

A company has deployed applications to thousands of Amazon EC2 instances in an AWS account. A security audit discovers that several unencrypted Amazon Elastic Block Store (Amazon EBS) volumes are attached to the EC2 instances. The company’s security policy requires the EBS volumes to be encrypted. The company needs to implement an automated solution to encrypt the EBS volumes. The solution also must prevent development teams from creating unencrypted EBS volumes. Which solution will meet these requirements?

  1. Configure the AWS Config managed rule that identifies unencrypted EBS volumes. Configure an automatic remediation action. Associate an AWS Systems Manager Automation runbook that includes the steps to create a new encrypted EBS volume. Create an AWS Key Management Service (AWS KMS) customer managed key. In the key policy, include a statement to deny the creation of unencrypted EBS volumes.
  2. Use AWS Systems Manager Fleet Manager to create a list of unencrypted EBS volumes, Create a Systems Manager Automation runbook that includes the steps to create a new encrypted EBS volume. Create an SCP to deny the creation of unencrypted EBS volumes.
  3. Use AWS Systems Manager Fleet Manager to create a list of unencrypted EBS volumes. Create a Systems Manager Automation runbook that includes the steps to create a new encrypted EBS volume. Modify the AWS account setting for EBS encryption to always encrypt new EBS volumes.
  4. Configure the AWS Config managed rule that identifies unencrypted EBS volumes. Configure an automatic remediation action. Associate an AWS Systems Manager Automation runbook that includes the steps to create a new encrypted EBS volume. Modify the AWS account setting for EBS encryption to always encrypt new EBS volumes. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The two requirements are solved by two different mechanisms: AWS Config with a remediation runbook handles the existing unencrypted volumes automatically, while the EBS encryption by default account setting makes every new volume encrypted at creation time.

A security audit found unencrypted EBS volumes attached to thousands of EC2 instances, and policy requires all of them to be encrypted. The company needs both an automated way to encrypt the existing volumes and a preventive control so development teams cannot create new unencrypted volumes.

Trying to enforce encryption with a key policy deny statement or an SCP. A deny on the KMS key does not block the CreateVolume call itself, and an SCP denying unencrypted volume creation is written around a condition that is evaluated at a different point, whereas the account setting applies encryption before the volume exists.

Community Discussion (8 comments)

AzureDP900 👍 2
Option D meet the requirements of automatically encrypting existing unencrypted EBS volumes and preventing development teams from creating unencrypted EBS volumes, you can configure an AWS Config managed rule that identifies unencrypted EBS volumes. The automatic remediation action should be to create a new encrypted EBS volume and replace the old one. Additionally, modifying the AWS account setting for EBS encryption to always encrypt new EBS volumes ensures that no more unencrypted EBS volumes are created in the future.
sammyhaj 👍 1 Selected: B
Issue is that NONE prevent new EBS volumes to be launched without encryption, albiet systems manager can remediate it isn't ideal. regardless you need a solution to PREVENT 100% unecrypted drives, and this is only done via SCP. other items can be circumvented by CLI
Daniel76 👍 2 Selected: D
https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/automatically-encrypt-existing-and-new-amazon-ebs-volumes.html 1. Use AWS Config to detects an unencrypted EBS volume. Not fleet manager. B and C out. 2. System manager runbook is the automation that create encrypted copy of the EBS snapshot and replace the encrypted EBS with the encrypted copy. The KMS is used for the encryption and it cannot be used to deny creation of unencrypted EBS volume (A is out).
PSPaul 👍 2
My answer is D Proactive Remediation: The AWS Config rule and Automation runbook identify and remediate existing unencrypted volumes automatically. Preventive Measure: The modified AWS account setting ensures that all new EBS volumes created in the account are automatically encrypted. This approach provides a comprehensive solution that addresses both existing unencrypted volumes and future volume creation. Why not Option A: While it addresses the issue of existing unencrypted volumes, it doesn't prevent future unencrypted volume creation.
vip2 👍 3 Selected: D
D is correct instead of A because AWS support change account setting for EBS encryption
Helpnosense 👍 2 Selected: D
Use config to find unencrypted EBS. Change the default setting.
kupo777 👍 2
D Enabling default encryption for EBSs prevents the creation of unencrypted EBSs.
awsaz 👍 2 Selected: D
the answer is D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The AWS Config managed rule for unencrypted EBS volumes continuously detects the existing unencrypted volumes, and configuring an automatic remediation action that invokes a Systems Manager Automation runbook encrypts them without manual intervention, which satisfies the first requirement at scale across thousands of instances. Modifying the account setting so that EBS encryption is always enabled for new volumes makes encryption the default at creation, so development teams can no longer produce unencrypted volumes even if they do not specify encryption, which satisfies the preventive requirement with no policy work per team.

Why the Other Options Are Wrong

A: A deny statement in a KMS key policy cannot prevent creation of an unencrypted volume, because an unencrypted volume does not use the key, and there is nothing in the key policy to deny at CreateVolume time. B and C: Systems Manager Fleet Manager can list instances but it is not a detection-and-remediation control for unencrypted volumes the way a Config managed rule with automatic remediation is, and neither option includes a preventive control. C in particular omits any prevention step, so development teams could immediately create new unencrypted volumes. D is the only option that pairs proactive remediation with the preventive account setting.

Community Comment Notes

The community voted 90 to 1 for D. Commenters pointed to the AWS prescriptive guidance pattern for automatically encrypting existing and new EBS volumes and confirmed the account setting, rather than an SCP or key policy, is what makes new volumes encrypted by default. The single dissenting vote for B correctly noted that Fleet Manager alone remediates but does not prevent.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide