AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A large enterprise is transitioning to a microservices architecture on AWS. They require that all newly provisioned EC2 instances automatically adhere to baseline security configurations, such as specific AMI versions, mandatory security groups, and encryption of EBS volumes. This compliance needs to be continuously monitored, and any non-compliant resources must be automatically remediated. Which combination of AWS services can achieve this goal?

  1. AAWS Config, AWS Systems Manager, and AWS Lambda
  2. BAmazon Inspector, AWS Security Hub, and AWS KMS
  3. CAWS Service Catalog, AWS Organizations, and AWS WAF
  4. DAWS CloudFormation, AWS CloudTrail, and Amazon EventBridge
Show answer & explanation

Correct answer: A. AWS Config, AWS Systems Manager, and AWS Lambda

AWS Config can define desired configurations and continuously monitor for compliance. When non-compliant resources are detected, AWS Config rules can trigger AWS Lambda functions for automated remediation actions. AWS Systems Manager can then be used by the Lambda function to apply the necessary security configurations (e.g., attach correct security groups, enable EBS encryption).

Why the other options are wrong

  • B. Inspector assesses vulnerabilities, Security Hub aggregates findings, and KMS manages encryption keys. While relevant to security, they don't provide the continuous compliance monitoring and automated remediation of resource configurations as a combined solution.
  • C. Service Catalog allows users to provision approved products. Organizations manages accounts. WAF protects web applications. None provide continuous compliance monitoring and automated remediation of general EC2 configurations.
  • D. CloudFormation provisions resources, CloudTrail logs API calls, and EventBridge routes events, but this combination doesn't inherently provide continuous compliance monitoring and automated remediation of *non-compliant* existing resources.

Continuous Compliance & Automated Remediation

Using AWS services to define desired resource configurations, continuously monitor for deviations, and automatically correct non-compliant resources.

  • AWS Config: Defines desired state, monitors for compliance.
  • AWS Lambda: Triggers automated remediation actions.
  • AWS Systems Manager: Executes remediation tasks on instances.
  • Ensures security baselines are maintained automatically.

Memory trick: Config 'watches', Lambda 'acts', Systems Manager 'fixes' for continuous compliance.

More Network Security, Compliance, and Governance questions