AnswerCorrect answer: A — deploy an org-wide Config aggregator and use a Lambda remediation to fix existing and future noncompliant S3 buckets.
A company uses AWS Config rules to identify Amazon S3 buckets that are not compliant with the company’s data protection policy. The S3 buckets are hosted in several AWS Regions and several AWS accounts. The accounts are in an organization in AWS Organizations. The company needs a solution to remediate the organization’s existing noncompliant S3 buckets and any noncompliant S3 buckets that are created in the future. Which solution will meet these requirements?
Deploy an AWS Config aggregator with organization-wide resource data aggregation. Create an AWS Lambda function that responds to AWS Config findings of noncompliant S3 buckets by deleting or reconfiguring the S3 buckets. Correct Answer
Deploy an AWS Config aggregator with organization-wide resource data aggregation. Create an SCP that contains a Deny statement that prevents the creation of new noncompliant S3 buckets. Apply the SCP to all OUs in the organization.
Deploy an AWS Config aggregator that scopes only the accounts and Regions that the company currently uses. Create an AWS Lambda function that responds to AWS Config findings of noncompliant S3 buckets by deleting or reconfiguring the S3 buckets.
Deploy an AWS Config aggregator that scopes only the accounts and Regions that the company currently uses. Create an SCP that contains a Deny statement that prevents the creation of new noncompliant S3 buckets. Apply the SCP to all OUs in the organization.
Community Votes
A
75%
B
25%
75% of anonymous learners picked answer A.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The requirement covers existing AND future noncompliant buckets. An org-wide Config aggregator gives the centralized view, and a Lambda remediation reacts to findings to fix existing buckets—something SCPs cannot do (SCPs only prevent new ones). A scopes the aggregator org-wide (better than C/D's limited scope) and includes the remediation Lambda, so A meets both parts. B's SCP-only approach fails the existing-bucket remediation.
To fix both existing and future noncompliant S3 buckets across many accounts and Regions, deploy an AWS Config aggregator with organization-wide aggregation for full visibility, and use a Lambda function triggered by Config findings to delete or reconfigure noncompliant buckets. SCPs alone only prevent future violations and cannot remediate what already exists, so the Lambda is required for the 'existing' part of the requirement.
Using only an SCP (B/D)—SCPs prevent future noncompliant buckets but cannot remediate the existing ones the requirement also mentions. Scoping the aggregator to only current accounts/Regions (C/D)—the org is multi-account/multi-Region, so an org-wide aggregator (A) gives complete visibility. A is the complete answer.
Community Discussion (4 comments)
phmeeeee👍 1Selected: A
A - Ensures visibility across all AWS accounts and Regions in the org and Lambda to remidiation non-complicnce resource. SCP is for prevention not remediation such a thing.
Pat9595👍 1Selected: A
SCPs only prevent future violations but do not remediate existing noncompliant S3 buckets. The requirement includes fixing already existing noncompliant S3 buckets, which SCPs alone cannot address.
Bachhu👍 1Selected: B
Seems like B as full AWS organisation.
Pmktechno👍 1Selected: A
AWS Config Aggregator: This allows you to aggregate AWS Config data from multiple accounts and Regions into a single account, providing a comprehensive view of compliance status across the organization. AWS Lambda Function: By creating a Lambda function that responds to noncompliant findings, you can automate the remediation process. This function can be configured to either delete or reconfigure noncompliant S3 buckets, ensuring they meet the company's data protection policy. This approach ensures that both existing and future noncompliant S3 buckets are addressed automatically, maintaining compliance across the organization.
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
An AWS Config aggregator with organization-wide aggregation provides a single view of compliance across all accounts and Regions, and a Lambda function responding to Config findings can delete or reconfigure noncompliant S3 buckets—remediating existing violations. Because the requirement explicitly includes fixing already-existing noncompliant buckets, the Lambda remediation is necessary; SCPs alone cannot retroactively fix them.
Why the Other Options Are Wrong
B and D rely on SCPs, which prevent future noncompliant buckets but do nothing for the existing ones the requirement also covers. C and D scope the aggregator to only currently used accounts/Regions, missing the org-wide visibility an organization aggregator (A) provides. A is the complete solution.
Community Comment Notes
Community voted A (75), with B a 25 minority. Commenters noted SCPs only prevent future violations and cannot remediate existing noncompliant buckets, so the Lambda remediation plus org-wide aggregator (A) is required. A confirmed.