AWS Certified Security – SpecialtyDomain 1: Incident ResponseHard

An organization is using AWS Control Tower for multi-account governance. A security incident is detected in one of the member accounts, requiring immediate lockdown of all network access to a specific AWS Region within that account. The security team needs to prevent any traffic from entering or leaving this Region, even for newly provisioned resources, as part of the containment strategy. Which AWS service and control type should be used to enforce this broad network lockdown?

  1. AService Control Policies (SCPs) enforced at the Organizational Unit (OU) level, denying network-related actions in the Region.
  2. BNetwork Access Control Lists (NACLs) configured on all subnets in the targeted Region.
  3. CAWS WAF Web ACLs applied to all Application Load Balancers in the Region.
  4. DSecurity Groups configured on all EC2 instances and other resources in the Region to deny all traffic.
Show answer & explanation

Correct answer: A. Service Control Policies (SCPs) enforced at the Organizational Unit (OU) level, denying network-related actions in the Region.

SCPs are ideal for enforcing broad, preventative controls across accounts or OUs. By denying network-related actions (e.g., 'ec2:*', 'network:*') in a specific Region, an SCP can effectively lockdown all network access, even preventing new resources from establishing network connectivity, as it applies at the API level.

Why the other options are wrong

  • B. NACLs provide subnet-level traffic filtering but are reactive and require manual configuration for every subnet, making them cumbersome for a full Region lockdown and not preventative for new resources.
  • C. AWS WAF protects web applications at Layer 7 and is not suitable for a broad network lockdown across an entire AWS Region or all service types.
  • D. Security Groups are instance/resource-level and reactive. Manually configuring them for all resources in a Region is impractical, and they won't prevent new resources from being launched with network access.

SCP for Regional Network Lockdown

Using AWS Organizations Service Control Policies (SCPs) to enforce a preventative, broad denial of all network-related AWS API actions within a specific AWS Region for an account or Organizational Unit.

  • Applies at the API level, preventing actions.
  • Effective across all AWS services in the scope.
  • Ideal for broad, preventative containment strategies.

Memory trick: SCPs are the regional border patrol for your AWS accounts.

More Domain 1: Incident Response questions