Use AWS Config with a restricted-ssh custom rule on the configuration-change trigger and Lambda remediation
During a security audit, a company discovered that some security groups allow SSH traffic from 0.0.0.0/0. A security team must implement a solution to detect and remediate this issue as soon as possible. The company uses one organization in AWS Organizations to manage all the company's AWS accounts. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The requirement is as soon as possible, so the trigger must be the configuration change trigger rather than a periodic one, which eliminates option A and points to the restricted-ssh rule on that trigger (C). Remediation must also be automatic rather than a report, which rules out option D's hourly Automation runs. Option B is wrong on two counts: it deletes all security group rules rather than only the offending SSH rule, which would break legitimate access, and it places a function and a rule in every account rather than using the organization's Config evaluation.
Security groups permitting SSH from 0.0.0.0/0 must be detected and remediated as soon as possible across all accounts in the organization. AWS Config is enabled in every account, a custom rule is created that runs on the restricted-ssh configuration change trigger so evaluation happens as soon as a security group changes rather than on a schedule, and the rule invokes an AWS Lambda function to remediate any noncompliant resource. Because the detection and the fix are both driven by Config's evaluation, the exposure is closed promptly without any scheduled job.
Using a periodic trigger with the vpc-sg-port-restriction-check rule (A) — phu0298 identified both problems, that the rule is not specific to the SSH-from-anywhere condition described, and that a periodic trigger does not provide real-time detection and delays remediation. phu0298 noted the same. Creating a Lambda in each account that deletes all security group rules, triggered by security group update or creation events (B) — this removes every rule rather than only the unrestricted SSH rule, which would disrupt all inbound access to every instance in the account, far exceeding the remediation required. Using a Systems Manager Automation document run every hour to inspect and delete noncompliant rules (D) — phu0298 and Slays both emphasized that the requirement is to act as soon as possible, and an hourly schedule leaves the exposure open for up to an hour after it appears.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is to detect and remediate unrestricted SSH access across all accounts as soon as possible. AWS Config provides continuous evaluation of resource configuration, and its configuration change trigger causes a rule to evaluate the moment a relevant resource such as a security group is modified, rather than waiting for a scheduled cycle (C). A custom rule is created using that trigger so that the evaluation happens immediately after any change to a security group, and the rule is configured to invoke an AWS Lambda function to remediate any noncompliant resource, which removes the offending rule automatically (C). Because Config is enabled in all accounts and is itself centrally governed, this gives organization-wide coverage with a single design, and the whole path from change to detection to remediation is event-driven, which satisfies the as soon as possible requirement. C is the correct answer.Why the Other Options Are Wrong
A enables AWS Config for all accounts, uses a periodic trigger to activate the vpc-sg-port-restriction-check rule, and creates a Lambda function to remediate noncompliant rules. As phu0298 identified, this fails on two counts: the vpc-sg-port-restriction-check rule evaluates whether security groups restrict ports in general and is not specific to the SSH-from-0.0.0.0/0 condition described, and a periodic trigger does not provide real-time detection, so remediation can be delayed until the next evaluation cycle. That directly contradicts the as soon as possible requirement. B creates a Lambda function in each account to delete all security group rules, with an EventBridge rule matching security group update or creation events as the trigger. Deleting all rules rather than only the unrestricted SSH rule would strip every inbound rule from every security group in the account, breaking legitimate access to all workloads, which is a vastly destructive action for the stated problem; it also distributes a function into every account rather than relying on the organization's Config evaluation. D creates a Systems Manager Automation document in each account to inspect security groups and delete noncompliant rules, invoked by an EventBridge rule every hour. Both phu0298 and Slays stressed that the requirement is to act as soon as possible, and an hourly schedule leaves a security group exposing SSH to the internet for up to an hour after it appears, so this does not meet the requirement. C is correct.Community Comment Notes
Community voted C unanimously. Srikantha characterized C as AWS Config plus real-time rule evaluation plus Lambda remediation, providing real-time security enforcement across all accounts. Slays explained that the option enables Config across all accounts, deploys the restricted-ssh rule, and sets up automatic remediation to address noncompliant security groups. phu0298 asked why not A and answered both objections precisely, that vpc-sg-port-restriction-check is not specific to this use case and that a periodic trigger delays remediation because it is not real-time. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →