A security audit reveals that several Amazon EC2 instances in a production environment are running with overly permissive IAM roles, granting access to services they do not require. The SysOps administrator needs to identify these instances and automatically reduce their permissions to the minimum necessary level. Which approach is the MOST efficient and compliant for continuous enforcement?
- AUse AWS Config to detect non-compliant instances and trigger an AWS Systems Manager Automation document to apply least privilege IAM policies.
- BManually review each EC2 instance's attached IAM role and modify the role policies using the IAM console.
- CImplement AWS Organizations Service Control Policies (SCPs) to restrict the maximum permissions available to all IAM roles in the account.
- DUtilize IAM Access Analyzer to identify unused permissions and then manually update the IAM role policies.
Show answer & explanationAnswer & explanation
Correct answer: A. Use AWS Config to detect non-compliant instances and trigger an AWS Systems Manager Automation document to apply least privilege IAM policies.
AWS Config is ideal for continuous monitoring of resource configurations, including attached IAM roles on EC2 instances. A custom Config rule can be set up to detect roles with overly permissive policies (e.g., using `iam:List*` or `*`). When non-compliance is detected, an AWS Systems Manager Automation document can be triggered to automatically remediate by attaching a more restrictive policy or detaching the overly permissive one, ensuring continuous least privilege enforcement without manual intervention. This is the most efficient and compliant approach for continuous, automated enforcement.
Why the other options are wrong
- B. Manual review and modification are time-consuming, prone to human error, and do not provide continuous, automated enforcement, failing the 'most efficient and compliant for continuous enforcement' requirement.
- C. SCPs restrict maximum permissions at the account or OU level, preventing roles from exceeding certain boundaries, but they do not automatically reduce existing overly permissive role policies on individual EC2 instances to the minimum necessary level based on actual usage or specific resource requirements. They are a guardrail, not an automated remediation tool for existing misconfigurations.
- D. IAM Access Analyzer is excellent for identifying unused permissions, but it's a detection tool. Manual updates still require human intervention and don't provide continuous automated enforcement.
Automated Least Privilege Enforcement
Combine AWS Config for continuous detection of overly permissive IAM roles on resources and AWS Systems Manager Automation for automated remediation to enforce least privilege.
- Config monitors IAM role compliance.
- Systems Manager Automation applies corrective actions.
- Ensures continuous enforcement.
- Reduces manual security overhead.
Memory trick: Config finds the flaws, Systems Manager fixes the fences.