AWS Certified SysOps Administrator – Associate — Question 88

A SysOps administrator is responsible for a company’s security groups. The company wants to maintain a documented trail of any changes that are made to the security groups. The SysOps administrator must receive notification whenever the security groups change.

Which solution will meet these requirements?

Answer options

Correct answer: C

Explanation

The correct answer is C because AWS Config is specifically designed to record and track changes in AWS resources, including security groups, and it can send notifications via Amazon SNS. Option A is incorrect as Amazon Detective is not used for change tracking, and SQS is not the preferred method for notification in this context. Option B suggests using AWS Systems Manager Change Manager, which is not the best fit for tracking security group changes. Option D incorrectly uses Amazon Detective again, which does not fulfill the requirement for tracking configuration changes.