A security team wants to automatically remediate S3 buckets that become publicly accessible. Which combination of AWS services achieves this with the least operational overhead?
-
A
AWS Config rule with an SSM Automation remediation document
-
B
CloudTrail with a Lambda function triggered by SNS
-
C
GuardDuty with a custom Lambda remediation function
-
D
Security Hub with a manual approval workflow