Last year’s review required KMS and VPC isolation. A new endpoint launched this month with neither, and nobody noticed until the audit. What should detect that drop continuously?
Select an answer to reveal the explanation.
Short Explanation
Last year's review required KMS and VPC isolation, and a new endpoint launched this month with neither. Use AWS Config rules that flag missing encryption or network settings and notify or remediate. A one-time CloudTrail search after the annual audit is too late.
Full Explanation
AWS Config rules continuously detect SageMaker resources that drop required KMS or VPC isolation and can notify or remediate. A one-time CloudTrail search after the audit is too late. Lex is not a Config rule, and Debugger does not watch endpoint encryption settings.