A governance team wants continuous evaluation that flags publicly accessible Amazon S3 buckets as noncompliant with city policy. Which AWS service is designed to evaluate resource configurations against such rules?
Select an answer to reveal the explanation.
Short Explanation
Config rules are like a nightly checklist that marks a public bucket as out of policy — continuous evaluation, not a one-time lecture. Transfer Acceleration speeds uploads, Snowball moves data offline, and CloudFront invalidations clear cache — none of those is the compliance rule engine.
Full Explanation
AWS Config supports continuous recording and rule-based evaluation of resource configurations, including checks commonly used to detect undesired public S3 settings. That capability directly supports governance and compliance monitoring. Transfer Acceleration, Snow Family devices, and CloudFront invalidations do not replace Config for configuration compliance evaluation.