AWS Certified Security – Specialty — Question 169

A security engineer is setting up a new AWS account. The engineer has been asked to continuously monitor the company's AWS account using automated compliance checks based on AWS best practices and Center for Internet Security (CIS) AWS Foundations Benchmarks.
How can the security engineer accomplish this using AWS services?

Answer options

Correct answer: A

Explanation

The correct answer is A because enabling AWS Config allows for continuous monitoring of resources and compliance checks, while AWS Security Hub provides a central view for security alerts and compliance status, including the CIS benchmarks. Options B and C incorrectly focus on Amazon Inspector, which does not provide the same level of continuous compliance monitoring as AWS Config. Option D also incorrectly suggests that Amazon Inspector can enforce compliance through AWS Config rules, which is not its primary function.