ExamQuestions.com

Register
Login
AWS Certified DevOps Engineer Professional Exam Questions

Amazon

AWS Certified DevOps Engineer Professional

483 / 500

Question 483:

You need to configure a new custom AWS Config rule to check whether EC2 security groups in your AWS account are compliant with the company’s security policies. One colleague has already created a Lambda function which you can use to perform the checks of security groups. For the Config rule, you would need to make sure that whenever there is a configuration change in any EC2 security group, the rule is triggered to evaluate the related security group resources. How would you specify the trigger of the Config rule?

Answer options:

A.In the Config rule trigger, specify the trigger type to be “Configuration changes” and configure the scope of changes to be “All changes” for all the EC2 resources.
B.Add a trigger in the Config rule, select the “Periodic” trigger type with a frequency of 1 hour and choose “EC2: SecurityGroup” in the trigger scope.
C.Create a trigger with the configuration change type and select the security group tag in the scope of changes. Make sure all existing and new security groups have the tag that you defined.
D.In the Config rule trigger, specify the trigger type to be “Configuration changes” and the scope of changes to be “EC2: SecurityGroup”.