Amazon S3 public access settings are critical for preventing inadvertent data exposure. AWS Config enables continuous monitoring of bucket compliance, while AWS Systems Manager Automation can automatically remediate any non-compliant resources.
In this Challenge Cloud Lab, you’ll be tested on your ability to configure AWS Config to monitor S3 buckets, enforce public access blocking, and implement automatic remediation via the runbook.
A high-level architecture diagram for this Challenge Cloud Lab is given below: