AWS Certified DevOps Engineer – ProfessionalIncident and Event ResponseMedium

A financial institution uses AWS for its critical transaction processing systems. They need to ensure that any unauthorized changes to security group rules are immediately detected and remediated. The solution must be automated, high-fidelity, and minimize human intervention to comply with strict regulatory requirements. Which combination of AWS services should the DevOps team implement to meet these requirements?

  1. AAWS Security Hub, AWS GuardDuty, Amazon SQS, and AWS Systems Manager.
  2. BAmazon CloudWatch Logs, Amazon SNS, AWS Step Functions, and AWS WAF.
  3. CAWS CloudTrail, Amazon EventBridge, AWS Lambda, and AWS Config Rules.
  4. DAWS Trusted Advisor, Amazon Macie, AWS Organizations, and AWS CodePipeline.
Show answer & explanation

Correct answer: C. AWS CloudTrail, Amazon EventBridge, AWS Lambda, and AWS Config Rules.

This solution leverages CloudTrail to capture API calls for security group changes, EventBridge to trigger an action based on these events, Lambda to perform the remediation, and AWS Config Rules to continuously monitor compliance and trigger remediation for non-compliant resources.

Why the other options are wrong

  • A. Security Hub and GuardDuty are for threat detection but not direct automated remediation of configuration changes. SQS and Systems Manager are not the most direct fit here.
  • B. While CloudWatch Logs and SNS can be part of monitoring, Step Functions and WAF are not the primary services for automated security group rule remediation based on changes.
  • D. Trusted Advisor provides recommendations, Macie for data discovery, Organizations for multi-account management, and CodePipeline for CI/CD, none of which directly address automated security group remediation.

Automated Remediation with AWS Config

Automated remediation uses AWS Config rules to detect non-compliant resources and automatically trigger actions (often via AWS Lambda) to restore them to a compliant state.

  • Detects configuration drift.
  • Triggers actions based on compliance status.
  • Reduces manual intervention for security and operational issues.

Memory trick: CloudTrail captures the change, EventBridge rings the bell, Lambda fixes the rule, Config keeps it well.

More Incident and Event Response questions