passdrill
AWS SAA-C03 · IAM & Security · Card 016/024 easy

A compliance team wants continuous visibility into whether every EBS volume in an account remains encrypted, with automatic flagging the moment a volume becomes non-compliant, plus a historical record of every configuration change made to that volume over time. Which service should they use?

  1. AWS Config, which continuously records configuration changes for supported resources and can evaluate them against managed or custom rules such as one that checks for encrypted volumes
  2. AWS CloudTrail, which logs the history of API calls made by users, roles, and services in the account
  3. Amazon Inspector, which scans EC2 instances and container images for known software vulnerabilities
  4. AWS Trusted Advisor, which provides a fixed set of best-practice checks refreshed on a set schedule
Next card → Shuffle