A security team needs to monitor the configuration of security groups across multiple AWS accounts in an AWS Organization. They require automatic remediation of non-compliant security group rules (e.g., overly permissive inbound rules like 0.0.0.0/0 on port 22 or 3389) and real-time alerts when such rules are detected. The solution should be scalable and minimize operational overhead. Which approach best meets these requirements?
- AManually review security group configurations across all accounts regularly and use AWS Chatbot for alerting.
- BDeploy AWS Config rules to detect non-compliant security groups and use AWS Systems Manager Automation documents for automatic remediation.
- CDevelop custom Lambda functions triggered by CloudWatch Events to periodically scan security groups and remove non-compliant rules.
- DUtilize Amazon GuardDuty to identify security groups with overly permissive rules and integrate with AWS Security Hub for reporting and alerts.
Show answer & explanationAnswer & explanation
Correct answer: B. Deploy AWS Config rules to detect non-compliant security groups and use AWS Systems Manager Automation documents for automatic remediation.
AWS Config provides managed or custom rules to evaluate AWS resource configurations for compliance. When a non-compliant security group is detected, an AWS Config rule can trigger an AWS Systems Manager Automation document to automatically remediate the issue (e.g., modify or remove the problematic rule), providing both detection and automatic remediation with minimal operational overhead.
Why the other options are wrong
- A. Manual review is not scalable, prone to human error, and does not provide real-time alerts or automatic remediation, failing to meet the core requirements.
- C. Developing and maintaining custom Lambda functions for scanning and remediation across multiple accounts can be complex and incur significant operational overhead compared to managed services.
- D. Amazon GuardDuty primarily focuses on threat detection based on network activity and API calls, not on continuous configuration compliance of security groups or automatic remediation of misconfigurations. Security Hub aggregates findings but doesn't perform the remediation itself.
AWS Config Rules with Remediation
AWS Config allows you to define rules to evaluate the configuration of your AWS resources. These rules can be integrated with AWS Systems Manager Automation for automatic remediation of non-compliant resources.
- Continuously monitors resource configurations.
- Detects non-compliant settings (e.g., overly permissive security groups).
- Enables automatic remediation using Systems Manager Automation documents.
- Scalable across multiple accounts and regions.
Memory trick: Config rules set the standard, Systems Manager fixes the flaws.