AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsMedium
A security auditor needs to periodically review all network access control lists (NACLs) and security groups (SGs) across multiple AWS accounts to ensure they comply with the company's least-privilege security policies. The auditor needs to quickly identify any overly permissive rules, such as ingress rules allowing '0.0.0.0/0' on sensitive ports, or egress rules allowing all outbound traffic. What is the most efficient and scalable AWS service to perform this type of continuous compliance auditing for network access controls?
- AAWS Config with custom rules
- BAWS CloudTrail with Amazon GuardDuty
- CVPC Flow Logs with Amazon Kinesis
- DAWS Security Hub with imported findings
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Config with custom rules
AWS Config is designed for continuous auditing of resource configurations against desired rules. By using AWS Config with either managed rules (e.g., `restricted-ssh`, `restricted-common-ports`) or custom Lambda-backed rules, the auditor can automatically evaluate NACLs and SGs across multiple accounts for compliance with least-privilege policies, making it highly efficient and scalable for this task.
Why the other options are wrong
- B. AWS CloudTrail logs API calls, and GuardDuty is a threat detection service. Neither is designed for continuous auditing of network access control *rules* for compliance with least-privilege policies.
- C. VPC Flow Logs capture traffic metadata, not the rules themselves. While useful for showing actual traffic, they don't audit the configured rules for permissiveness.
- D. AWS Security Hub aggregates security findings but doesn't perform the direct, continuous configuration auditing of NACL/SG rules itself. It would display findings from services like Config, but Config is the service performing the actual audit.
Config for Network ACL/SG Audit
AWS Config continuously monitors and evaluates Network ACLs and Security Groups against defined rules for compliance with security policies, identifying overly permissive configurations.
- Continuous configuration auditing
- Uses managed or custom rules
- Identifies overly permissive NACL/SG rules
- Scalable across multiple accounts
Memory trick: Config: Your network's rulebook enforcer, always checking for open doors.