Soru

Zorluk: OrtaAutomating Deployment and Configuration Management

A company uses AWS CloudFormation StackSets to deploy application infrastructure across multiple AWS accounts in an AWS Organization. The application requires secure, cross-account access to environment-specific credentials stored in a central operations account. The infrastructure team has also noticed that local administrators occasionally perform manual configuration changes directly on the resources within their individual accounts, leading to configuration drift. The Solutions Architect needs to implement a solution that automates drift detection and remediation while securing the cross-account dynamic parameters. Which of the following actions should the Solutions Architect take to meet these requirements? (Select TWO.)

  1. Encrypt the credentials in AWS Systems Manager Parameter Store using an AWS KMS Customer Managed Key (CMK), and update the key policy to grant decryption permissions to the application roles in the target accounts.Cevap
  2. Deploy AWS Systems Manager State Manager associations to automatically enforce and remediate configuration consistency on the managed instances, and use AWS CloudFormation drift detection to identify stack-level resource changes.Cevap
  3. C
    Encrypt the credentials in AWS Systems Manager Parameter Store using the default AWS-managed KMS key (aws/ssm), and configure its policy to delegate read and decrypt permissions to the target accounts.
  4. D
    Apply a Service Control Policy (SCP) at the Organizational Unit (OU) level that explicitly permits access to the Parameter Store resources in the central operations account, assuming this inherits downstream permissions.
  5. E
    Configure the CloudFormation StackSets to automatically delete and recreate the stacks daily to overwrite any manual modifications and reset resource configurations.

Cevap

The correct solution involves utilizing a Customer Managed Key (CMK) in AWS KMS to allow cross-account key policy configurations, and using AWS Systems Manager State Manager associations in tandem with CloudFormation drift detection to enforce configuration and check for stack modifications.
The correct actions involve deploying Systems Manager State Manager associations to continuously enforce configurations and using CloudFormation drift detection to verify infrastructure compliance, while using a Customer Managed Key (CMK) in KMS to securely permit cross-account decryption of dynamic parameters.

Adım Adım Çözüm

1
Determine how to safely share encrypted parameters across accounts.
Select the option that configures Systems Manager Parameter Store with a Customer Managed Key (CMK).
AWS-managed KMS keys do not support key policy modifications and cannot be shared with external or child AWS accounts.
2
Identify the appropriate mechanisms for infrastructure drift detection and configuration enforcement.
Deploy Systems Manager State Manager associations alongside CloudFormation drift detection.
This combination allows continuous enforcement of configuration compliance on the instances while maintaining stack integrity checks.

Anahtar Kavram

Cross-account AWS KMS resource policies and automatic configuration drift remediation
Tahmini Süre:2m 0s
Bu soruyu puanla