AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium
A security engineer needs to monitor and audit the security configuration of all EC2 instances across multiple AWS accounts in an organization. Specifically, they need to ensure that all EC2 instances are launched with specific IAM roles, are tagged correctly, and do not have public IP addresses unless explicitly approved. The solution should provide continuous compliance assessment and generate alerts for non-compliant resources. Which AWS service should be used to achieve this?
- AAmazon CloudWatch
- BAmazon GuardDuty
- CAWS CloudTrail
- DAWS Config
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Config
AWS Config continuously monitors and records AWS resource configurations and allows you to automate the evaluation of recorded configurations against desired configurations. It can track IAM roles, tags, public IP assignments, and generate compliance status and alerts, perfectly matching the requirements.
Why the other options are wrong
- A. Amazon CloudWatch is primarily for monitoring metrics and logs, and while it can alert on some configuration changes, it doesn't provide the comprehensive configuration assessment capabilities of AWS Config.
- B. Amazon GuardDuty is a threat detection service, focusing on malicious activity and unauthorized behavior, not on ensuring adherence to configuration policies.
- C. AWS CloudTrail records API calls and events, which is useful for auditing actions but not for continuous assessment of resource configurations against desired states.
AWS Config
A service that enables you to assess, audit, and evaluate the configurations of your AWS resources.
- Records configuration changes over time
- Evaluates against desired configurations (rules)
- Provides compliance status and generates alerts
Memory trick: Config checks your stuff, making sure it's tough.