AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard
A security auditor discovers that a company's AWS environment has several Amazon EC2 instances with overly permissive security group rules, allowing SSH (port 22) and RDP (port 3389) access from '0.0.0.0/0'. This poses a significant security risk. The company needs to implement a solution to centrally manage and automatically enforce strict security group rules across all existing and newly created AWS accounts and VPCs in its AWS Organization, ensuring that such permissive rules are never deployed. Which AWS service combination should be used?
- AAWS WAF with AWS Shield Advanced
- BAmazon GuardDuty with AWS CloudTrail
- CAWS Config with Security Hub
- DAWS Firewall Manager with AWS Organizations
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Firewall Manager with AWS Organizations
AWS Firewall Manager is designed to centrally configure and manage firewall rules across multiple accounts and VPCs within an AWS Organization. It can detect and automatically remediate non-compliant security groups, ensuring that overly permissive rules like '0.0.0.0/0' for SSH/RDP are prevented or corrected, fulfilling the requirement for centralized enforcement across the entire organization.
Why the other options are wrong
- A. AWS WAF protects web applications, and AWS Shield Advanced provides DDoS protection; neither addresses the centralized management and enforcement of security group rules.
- B. Amazon GuardDuty detects threats and CloudTrail logs API calls; neither directly prevents or enforces security group rules across an organization.
- C. AWS Config can detect non-compliance, and Security Hub aggregates findings, but neither automatically enforces or prevents the deployment of non-compliant security groups across an entire organization without additional automation.
AWS Firewall Manager
A security management service that allows you to centrally configure and manage firewall rules across your accounts and applications in AWS Organizations.
- Integrates with AWS Organizations for multi-account management.
- Can manage AWS WAF, AWS Shield Advanced, Security Groups, and AWS Network Firewall rules.
- Automatically remediates non-compliant resources.
Memory trick: The 'MANAGER' of 'ORGANIZATIONS' keeps policies tight.