A SysOps administrator needs to ensure that all Amazon S3 buckets in an AWS account are configured with server-side encryption using AWS KMS (SSE-KMS). The administrator wants to automatically detect any S3 buckets that are not compliant and remediate them by enabling SSE-KMS. Which AWS service should be used to implement this automated compliance enforcement?
AWS Config continuously evaluates S3 bucket configurations against managed rules such as s3-bucket-server-side-encryption-enabled, which specifically verifies that default encryption is set to SSE-KMS. When a bucket is non-compliant, AWS Config can automatically invoke an SSM automation document (e.g., AWS-EnableS3BucketEncryption) to remediate the violation, enforcing SSE-KMS without manual intervention. This real-time monitoring and automated remediation capability is exactly what the SysOps administrator needs to ensure all S3 buckets meet the encryption requirement.
Why this answer
AWS Config is the correct service because it provides managed rules (e.g., s3-bucket-server-side-encryption-enabled) that can continuously evaluate S3 buckets for compliance with SSE-KMS. When a non-compliant bucket is detected, AWS Config can trigger an AWS Systems Manager Automation document or a custom remediation action (via AWS Config Rules remediation) to automatically enable SSE-KMS on the bucket, ensuring automated enforcement without manual intervention.
Exam trap
The trap here is that candidates often confuse AWS Config's reactive compliance monitoring with Trusted Advisor's advisory checks, or assume CloudFormation can handle post-deployment compliance, but only AWS Config provides the continuous evaluation and automated remediation required for this use case.
How to eliminate wrong answers
Option B is wrong because AWS Trusted Advisor only provides reactive recommendations and best-practice checks (e.g., S3 bucket permissions) but does not support automated remediation or custom compliance rules; it cannot automatically enable SSE-KMS on non-compliant buckets. Option C is wrong because AWS Service Catalog is used to create and manage a catalog of approved IT services (e.g., pre-configured S3 bucket templates) but does not perform ongoing compliance monitoring or remediation of existing resources. Option D is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources via templates; it can enforce SSE-KMS at deployment time but cannot automatically detect or remediate non-compliant buckets that already exist or are created outside of CloudFormation stacks.