AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium
A compliance officer requires a solution to periodically audit the security group rules across all AWS accounts in an organization to ensure that no overly permissive inbound rules (e.g., SSH or RDP from 0.0.0.0/0) are configured. The solution needs to generate a compliance report and trigger an alert if any non-compliant rules are found. Which AWS services should be used to achieve this?
- AAWS Config with a managed rule for restricted SSH/RDP and an SNS topic for notifications.
- BAmazon GuardDuty for threat detection and Amazon EventBridge for custom events.
- CAWS Security Hub for security findings aggregation and AWS Firewall Manager for centralized rule management.
- DAWS Trusted Advisor for security checks and AWS Health Dashboard for alerts.
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Config with a managed rule for restricted SSH/RDP and an SNS topic for notifications.
AWS Config is ideal for continuously auditing resource configurations against desired policies. The managed rule `restricted-ssh` or `restricted-common-ports` can directly detect overly permissive inbound rules for SSH/RDP. When non-compliant resources are found, Config can send notifications to an SNS topic, triggering alerts.
Why the other options are wrong
- B. GuardDuty is a threat detection service, not a configuration compliance auditing tool for security groups. EventBridge can route events, but Config is the source of the compliance findings.
- C. Security Hub aggregates findings, but Config is the service that *generates* the finding for security group non-compliance. Firewall Manager centralizes WAF/Shield/SG rules, but Config *audits* the actual configurations against policies.
- D. Trusted Advisor provides periodic checks and recommendations, but it's not a continuous compliance engine for custom rules, nor does Health Dashboard provide alerts for Config rule non-compliance.
AWS Config for Security Group Compliance
AWS Config continuously audits security group rules using managed or custom rules to ensure compliance with security policies, alerting on non-compliant configurations.
- AWS Config evaluates resource configurations against desired states.
- Managed rules exist for common security best practices (e.g., restricted SSH).
- Non-compliant findings can trigger notifications via SNS.
- Provides a compliance timeline and history for audited resources.
Memory trick: Config checks security doors, warns if they're too wide, no more.