Soru

Zorluk: OrtaSecurity Monitoring, Logging, and Compliance Auditing

A SysOps Administrator needs to aggregate compliance status data from AWS Config rules across all member accounts within an AWS Organization. The administrator wants to view the compliance details of all accounts and regions in a single dashboard within the organization's management account with the least administrative effort. Which solution will meet these requirements?

  1. Set up an AWS Config aggregator in the management account, and configure it to collect compliance data from the entire AWS Organization.Cevap
  2. B
    Create an Amazon EventBridge rule in each member account to detect Config compliance state changes, and route the events to a central Amazon SNS topic in the management account.
  3. C
    Configure a cross-account IAM role in each member account, and use the iam:PassRole permission in the management account to query each Config service endpoint.
  4. D
    Create an AWS Config delivery channel in each member account that writes history files to a centralized Amazon S3 bucket, then stream these logs to Amazon CloudWatch Logs for analysis.

Cevap

Set up an AWS Config aggregator in the management account, and configure it to collect compliance data from the entire AWS Organization.
An AWS Config aggregator is an AWS Config resource type that collects configuration history and compliance data from multiple accounts and regions. Creating an aggregator in the management account of an AWS Organization allows the administrator to view compliance status across all accounts and regions in a single dashboard with minimal effort, making this the correct and most efficient solution.

Adım Adım Çözüm

1
Identify the requirement to aggregate compliance data across all AWS accounts and regions in an AWS Organization.
Confirming AWS Config supports multi-account multi-region data aggregation.
This determines that a native aggregation capability is the preferred path to minimize administrative overhead.
2
Create an aggregator resource in the AWS Config console of the organization's management account.
The aggregator is configured to collect data from the entire AWS Organization, utilizing the organization's service-linked role.
This authorizes AWS Config to gather data from all member accounts without manual configuration in each individual account.
3
Verify compliance status from the central dashboard.
The management account dashboard displays the aggregated compliance status of all Config rules.
This fulfills the compliance monitoring requirement with the least effort.

Anahtar Kavram

AWS Config Multi-Account Multi-Region Data Aggregation
Bu soruyu puanla