Question 481:
Your team has configured several AWS Config rules in an AWS account. You just took a long holiday but when you come back to work, you find that an AWS Config rule has become non-compliant for an important S3 bucket resource. The rule is used to check if S3 bucket resources have the bucket policy that denies the incoming insecure requests. You remember that before you took the holiday, this Config rule was compliant for all S3 buckets. You want to quickly check when and how this bucket became non-compliant. Which option is the easiest one?
Answer options:
A.In AWS Config, open the configuration timeline, check each change that was performed during your holiday and find the one that changed the bucket policy. B.Open the compliance timeline of the resource in AWS Config and check the changes when the rule status became non-compliant. C.In the AWS CloudTrail console, search your S3 bucket name, open each CloudTrail event and locate the event that is related to the bucket policy. D.In AWS CloudTrail, search the bucket policy events and check each event to see if it is about this particular S3 bucket.