AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsMedium

A security auditor needs to periodically review all network access control lists (NACLs) and security groups (SGs) across multiple AWS accounts to ensure they comply with the company's least-privilege security policies. The auditor needs to quickly identify any overly permissive rules, such as ingress rules allowing '0.0.0.0/0' on sensitive ports, or egress rules allowing all outbound traffic. What is the most efficient and scalable AWS service to perform this type of continuous compliance auditing for network access controls?

  1. AAWS Config with custom rules
  2. BAWS CloudTrail with Amazon GuardDuty
  3. CVPC Flow Logs with Amazon Kinesis
  4. DAWS Security Hub with imported findings
Show answer & explanation

Correct answer: A. AWS Config with custom rules

AWS Config is designed for continuous auditing of resource configurations against desired rules. By using AWS Config with either managed rules (e.g., `restricted-ssh`, `restricted-common-ports`) or custom Lambda-backed rules, the auditor can automatically evaluate NACLs and SGs across multiple accounts for compliance with least-privilege policies, making it highly efficient and scalable for this task.

Why the other options are wrong

  • B. AWS CloudTrail logs API calls, and GuardDuty is a threat detection service. Neither is designed for continuous auditing of network access control *rules* for compliance with least-privilege policies.
  • C. VPC Flow Logs capture traffic metadata, not the rules themselves. While useful for showing actual traffic, they don't audit the configured rules for permissiveness.
  • D. AWS Security Hub aggregates security findings but doesn't perform the direct, continuous configuration auditing of NACL/SG rules itself. It would display findings from services like Config, but Config is the service performing the actual audit.

Config for Network ACL/SG Audit

AWS Config continuously monitors and evaluates Network ACLs and Security Groups against defined rules for compliance with security policies, identifying overly permissive configurations.

  • Continuous configuration auditing
  • Uses managed or custom rules
  • Identifies overly permissive NACL/SG rules
  • Scalable across multiple accounts

Memory trick: Config: Your network's rulebook enforcer, always checking for open doors.

More Network Management and Operations questions