AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsMedium
A security-conscious organization needs to ensure that all network configurations in their AWS environment adhere to strict internal policies and regulatory compliance standards. They want to automate the detection of non-compliant network configurations, such as security groups with overly permissive rules or unapproved Network ACL changes, and ideally, automatically remediate these issues. Which two AWS services, when combined, provide the most robust solution for continuous auditing and automated remediation of network configurations?
- AAWS Config and AWS Systems Manager Automation
- BAWS Security Hub and AWS WAF
- CAmazon CloudWatch Events and AWS Lambda
- DAWS CloudTrail and Amazon SNS
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Config and AWS Systems Manager Automation
AWS Config provides continuous monitoring and recording of AWS resource configurations, evaluating them against desired rules. When Config detects a non-compliant network configuration (e.g., a security group rule violation), it can trigger AWS Systems Manager Automation documents to automatically remediate the issue, creating a robust solution for continuous auditing and automated remediation.
Why the other options are wrong
- B. AWS Security Hub aggregates findings from various security services, and AWS WAF protects web applications. Neither directly provides continuous network configuration auditing and automated remediation in the way Config and Systems Manager do.
- C. CloudWatch Events (now EventBridge) and Lambda can trigger actions based on events, but Config provides the continuous configuration assessment and compliance rules needed for this scenario.
- D. AWS CloudTrail records API calls for auditing, and SNS sends notifications. While useful for alerting, they don't provide the continuous configuration assessment and automated remediation capabilities of Config and Systems Manager.
Config & Systems Manager Automation
AWS Config continuously evaluates AWS resource configurations against rules, and AWS Systems Manager Automation provides capabilities to automatically remediate non-compliant resources.
- Config for continuous compliance auditing
- Systems Manager Automation for automated remediation
- Detects and fixes configuration drift
- Supports network resources (SGs, NACLs)
Memory trick: Config checks the rules, Systems Manager fixes the breaks.