AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A company policy mandates that all EC2 instances must be automatically terminated if they are found to be non-compliant with a specific security group configuration (e.g., allowing SSH from 0.0.0.0/0). The SysOps team needs to implement a solution that continuously monitors the EC2 instances and automatically enforces this termination policy. Which AWS service should be used?

  1. AAmazon GuardDuty and AWS Lambda.
  2. BAWS CloudTrail and Amazon EventBridge rules.
  3. CAWS Security Hub and AWS Step Functions.
  4. DAWS Config with a custom rule and a remediation action.
Show answer & explanation

Correct answer: D. AWS Config with a custom rule and a remediation action.

AWS Config is designed for continuous monitoring of resource configurations. A custom Config rule can be created to detect EC2 instances with non-compliant security groups. Upon detection, an automated remediation action, such as a Lambda function to terminate the instance, can be triggered to enforce the policy.

Why the other options are wrong

  • A. GuardDuty is for threat detection (malicious activity), not for enforcing configuration compliance on security groups.
  • B. CloudTrail logs API calls and EventBridge can react to events, but Config provides the continuous compliance evaluation and direct remediation framework.
  • C. Security Hub aggregates findings, and Step Functions orchestrate workflows, but neither directly provides the continuous configuration compliance and automated remediation capability of Config.

AWS Config Remediation

AWS Config Remediation enables automatic correction of non-compliant resources based on predefined rules, ensuring continuous adherence to security and operational standards.

  • Uses AWS Config rules to detect non-compliance.
  • Supports both AWS-managed and custom rules.
  • Automated remediation actions are often implemented with AWS Lambda.
  • Helps maintain desired configuration state and compliance posture.

Memory trick: Config Rules Detect, Remediate to Terminate Non-Compliant EC2s.

More Security and Compliance questions