Amazon DOP-C02 Exam - Topic 5 Question 35 Discussion
A DevOps learn has created a Custom Lambda rule in AWS Config. The rule monitors Amazon Elastic Container Repository (Amazon ECR) policy statements for ecr:' actions. When a noncompliant repository is detected, Amazon EventBridge uses Amazon Simple Notification Service (Amazon SNS) to route the notification to a security team.When the custom AWS Config rule is evaluated, the AWS Lambda function fails to run.Which solution will resolve the issue?
A) Modify the Lambda function's resource policy to grant AWS Config permission to invoke the function.
B) Modify the SNS topic policy to include configuration changes for EventBridge to publish to the SNS topic.
C) Modify the Lambda function's execution role to include configuration changes for custom AWS Config rules.
D) Modify all the ECR repository policies to grant AWS Config access to the necessary ECR API actions.
Step 1: Understanding Lambda Permissions and AWS Config
The custom AWS Config rule evaluates resources and invokes an AWS Lambda function when a compliance check is triggered. For AWS Config to invoke the Lambda function, it requires permission to do so.
Issue: The Lambda function fails to execute because AWS Config doesn't have permission to invoke it.
Action: Modify the resource-based policy of the Lambda function to grant AWS Config permission to invoke the Lambda function.
Why: Without this permission, AWS Config cannot trigger the Lambda function, which is why the evaluation fails.
Donette
6 months agoLauran
6 months agoSelene
7 months agoAnika
7 months agoTerina
7 months agoShaunna
7 months agoNikita
7 months agoGeorgeanna
8 months agoGail
8 months agoRose
8 months agoNu
8 months agoLouvenia
8 months agoVi
8 months agoLottie
8 months agoAriel
2 years agoTenesha
2 years agoShay
2 years agoGarry
2 years agoHolley
2 years agoNan
2 years agoLonny
2 years agoMee
2 years agoMarquetta
2 years agoHelaine
2 years agoWai
2 years agoLevi
2 years agoAvery
2 years agoJess
2 years agoSabra
2 years agoFausto
2 years agoLeah
2 years agoIndia
2 years agoKent
2 years agoSocorro
2 years agoDyan
2 years ago