AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A global enterprise needs to enforce strict, consistent security policies across hundreds of AWS accounts and VPCs. These policies include ensuring that all Amazon S3 buckets are encrypted by default, all EC2 instances use approved AMIs, and specific network traffic patterns are blocked at the perimeter. The solution must provide centralized management and automated remediation for non-compliant resources. Which AWS service is best suited for this comprehensive governance and compliance requirement?

  1. AAWS Config
  2. BAWS Firewall Manager
  3. CAWS Organizations Service Control Policies (SCPs)
  4. DAWS Security Hub
Show answer & explanation

Correct answer: A. AWS Config

AWS Config continuously monitors and records AWS resource configurations, allowing evaluation against desired configurations. It can be integrated with AWS Lambda for automated remediation of non-compliant resources. While SCPs restrict actions, and Firewall Manager centralizes network rules, AWS Config provides the comprehensive monitoring and remediation framework for resource-level compliance across accounts.

Why the other options are wrong

  • B. AWS Firewall Manager centralizes firewall rule management across accounts but does not cover S3 encryption or EC2 AMI compliance; it's focused on network security rules.
  • C. SCPs define maximum permissions for accounts in an organization and can prevent non-compliant actions, but they don't monitor existing resources for compliance or provide automated remediation for configuration drifts.
  • D. AWS Security Hub aggregates security findings but doesn't directly provide automated remediation or enforce resource configuration policies.

AWS Config for Governance

AWS Config continuously monitors and records AWS resource configurations, evaluates compliance against policies, and facilitates automated remediation.

  • Provides a detailed configuration history of AWS resources.
  • Allows defining rules to check for desired configuration compliance.
  • Can trigger AWS Lambda functions for automated remediation of non-compliant resources.
  • Operates across multiple accounts when integrated with AWS Organizations.

Memory trick: Config checks and fixes everything, every resource, every rule.

More Network Security, Compliance, and Governance questions