AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationMedium

A security team needs to be notified whenever a security group's ingress or egress rules are modified in any AWS account within their organization. The notification should include details of the change and the affected resource. The solution must be automated and operate in near real-time.

  1. AImplement AWS GuardDuty to monitor for unusual API activity related to security groups and send findings to Amazon Security Hub.
  2. BEnable AWS Config rules to detect security group changes and trigger an Amazon SNS notification upon non-compliance.
  3. CConfigure Amazon CloudWatch Alarms to monitor the `NetworkIn` and `NetworkOut` metrics for all EC2 instances.
  4. DSet up Amazon EventBridge to capture `EC2 ModifySecurityGroupRules` API calls from AWS CloudTrail and route them to an Amazon SNS topic.
Show answer & explanation

Correct answer: D. Set up Amazon EventBridge to capture `EC2 ModifySecurityGroupRules` API calls from AWS CloudTrail and route them to an Amazon SNS topic.

EventBridge can directly consume CloudTrail events, including specific API calls like `ModifySecurityGroupRules`. By filtering for these events and routing them to an SNS topic, the security team receives near real-time notifications with full event details.

Why the other options are wrong

  • A. GuardDuty focuses on threat detection and unusual activity, not on direct notification for every security group rule modification as a compliance or audit requirement.
  • B. AWS Config can detect changes and assess compliance, but EventBridge provides more immediate and direct notification for specific API calls captured by CloudTrail.
  • C. Monitoring network traffic metrics does not directly notify about security group rule modifications; it's a symptom, not the change event itself.

EventBridge for CloudTrail API Events

Amazon EventBridge can act as a central event bus to receive and filter events from various AWS services, including specific API call events captured by AWS CloudTrail, enabling real-time automated responses.

  • EventBridge integrates with CloudTrail as a source.
  • Rule patterns can filter for specific API calls (e.g., `ModifySecurityGroupRules`).
  • Can route filtered events to targets like SNS for notifications or Lambda for automation.
  • Provides near real-time event processing.

Memory trick: CloudTrail sees the change, EventBridge sends the message.

More Monitoring, Logging, and Remediation questions