AWS Certified Security - Specialty (#13)

The InfoSec team has mandated that in the future only approved Amazon Machine Images (AMIs) can be used. How can the InfoSec team ensure compliance with this mandate?

Terminate all Amazon EC2 instances and relaunch them with approved AMIs.
Patch all running instances by using AWS Systems Manager.
Deploy AWS Config rules and check all running instances for compliance.
Define a metric filter in Amazon CloudWatch Logs to verify compliance.