AWS Service
AWS Config
AWS Config records resource configuration history and evaluates rules against desired configuration.
What This Service Solves
AWS Config records resource configuration history and evaluates rules against desired configuration.
- Use Config to detect drift, noncompliance, and configuration changes over time.
When You Should Not Use It
- Do not use Config when the question asks for application logs or user API history by itself.
What AWS Manages and What You Manage
AWS records supported configuration items. You manage recorder scope, rules, aggregators, remediation, and retention.
Security Implications
Config rules can flag public buckets, unencrypted volumes, and open security groups, but remediation still needs design.
Availability and Scaling
Config improves governance visibility. It does not make resources highly available.
Organization aggregators help centralize multi-account evidence.
Cost Behavior
Costs depend on configuration items, rule evaluations, and conformance packs.
Common Integrations
- Organizations
- Systems Manager Automation
- Security Hub
- CloudTrail
How AWS Might Present It
Certification-Specific Depth
CloudOps Engineer Associate
Know configuration choices, integrations, failure modes, security, operations, and cost tradeoffs.
Related Comparisons
Sources and Review Metadata
This independent training application is not affiliated with or endorsed by Amazon Web Services. AWS, Amazon Web Services, and AWS certification names are trademarks of Amazon.com, Inc. or its affiliates.