Answers
Here are the answers to this chapter’s questions:
- Conformance packs bundle together a group of Config rules and remediation actions, providing a unified approach to enforce compliance and security rules across multiple AWS accounts.
- Tags categorize resources for specific remediation actions based on their purpose or sensitivity. For instance, resources tagged as Critical might trigger immediate escalated responses, while those tagged as Non-essential may follow a standard remediation process.
- Security Hub facilitates compliance benchmarking by providing access to industry benchmarks, customizable frameworks for compliance assessment, a scoring system for compliance levels, and detailed compliance reporting.