AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium

A compliance officer requires a solution to periodically audit the security group rules across all AWS accounts in an organization to ensure that no overly permissive inbound rules (e.g., SSH or RDP from 0.0.0.0/0) are configured. The solution needs to generate a compliance report and trigger an alert if any non-compliant rules are found. Which AWS services should be used to achieve this?

  1. AAWS Config with a managed rule for restricted SSH/RDP and an SNS topic for notifications.
  2. BAmazon GuardDuty for threat detection and Amazon EventBridge for custom events.
  3. CAWS Security Hub for security findings aggregation and AWS Firewall Manager for centralized rule management.
  4. DAWS Trusted Advisor for security checks and AWS Health Dashboard for alerts.
Show answer & explanation

Correct answer: A. AWS Config with a managed rule for restricted SSH/RDP and an SNS topic for notifications.

AWS Config is ideal for continuously auditing resource configurations against desired policies. The managed rule `restricted-ssh` or `restricted-common-ports` can directly detect overly permissive inbound rules for SSH/RDP. When non-compliant resources are found, Config can send notifications to an SNS topic, triggering alerts.

Why the other options are wrong

  • B. GuardDuty is a threat detection service, not a configuration compliance auditing tool for security groups. EventBridge can route events, but Config is the source of the compliance findings.
  • C. Security Hub aggregates findings, but Config is the service that *generates* the finding for security group non-compliance. Firewall Manager centralizes WAF/Shield/SG rules, but Config *audits* the actual configurations against policies.
  • D. Trusted Advisor provides periodic checks and recommendations, but it's not a continuous compliance engine for custom rules, nor does Health Dashboard provide alerts for Config rule non-compliance.

AWS Config for Security Group Compliance

AWS Config continuously audits security group rules using managed or custom rules to ensure compliance with security policies, alerting on non-compliant configurations.

  • AWS Config evaluates resource configurations against desired states.
  • Managed rules exist for common security best practices (e.g., restricted SSH).
  • Non-compliant findings can trigger notifications via SNS.
  • Provides a compliance timeline and history for audited resources.

Memory trick: Config checks security doors, warns if they're too wide, no more.

More Domain 2: Logging and Monitoring questions