AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A security audit reveals that several Amazon EC2 instances in a production environment are running with overly permissive IAM roles, granting access beyond their operational requirements. The security team wants to implement a solution that automatically identifies and remediates these instances by applying the principle of least privilege. Which AWS service should be used to automate this process?

  1. AAmazon GuardDuty
  2. BAWS Config with a custom rule and remediation action.
  3. CAWS Trusted Advisor
  4. DAWS Security Hub
Show answer & explanation

Correct answer: B. AWS Config with a custom rule and remediation action.

AWS Config allows you to define custom rules to evaluate compliance of AWS resources, such as EC2 instances with attached IAM roles. When a non-compliant resource is detected (e.g., an EC2 instance with an overly permissive role), a remediation action can be automatically triggered, such as replacing the role with a more restrictive one.

Why the other options are wrong

  • A. GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not for enforcing least privilege on IAM roles.
  • C. Trusted Advisor provides recommendations but does not automate remediation of security findings.
  • D. Security Hub aggregates security findings but does not directly automate the remediation of non-compliant IAM roles on EC2 instances.

Automated Least Privilege Enforcement

Automated least privilege enforcement involves continuously monitoring resource permissions and automatically adjusting them to grant only the necessary access, reducing the attack surface.

  • AWS Config monitors resource configurations.
  • Custom Config rules can define compliance for IAM roles.
  • Remediation actions can automatically adjust non-compliant permissions.
  • Helps maintain security posture and compliance.

Memory trick: Config Rules Detect, Remediate Overly Permissive Roles.

More Security and Compliance questions