Use AWS Config with a restricted-ssh custom rule on the configuration-change trigger and Lambda remediation

Answer Correct answer: C — run a restricted-ssh Config custom rule on the configuration-change trigger with Lambda remediation.

During a security audit, a company discovered that some security groups allow SSH traffic from 0.0.0.0/0. A security team must implement a solution to detect and remediate this issue as soon as possible. The company uses one organization in AWS Organizations to manage all the company's AWS accounts. Which solution will meet these requirements?

  1. Enable AWS Config for all AWS accounts. Use a periodic trigger to activate the vpe-sg-port-restriction-check AWS Config rule. Create an AWS Lambda function to remediate any noncompliant rules.
  2. Create an AWS Lambda function in each AWS account to delete all the security group rules. Create an Amazon EventBridge rule to match security group update events or creation events. Set the Lambda function in each account as a target for the rule.
  3. Enable AWS Config for all AWS accounts. Create a custom AWS Config rule to run on the restricted-ssh configuration change trigger. Configure the rule to invoke an AWS Lambda function to remediate any noncompliant resources. Correct Answer
  4. Create an AWS Systems Manager Automation document in each account to inspect all security groups and to delete noncompliant rules. Use an Amazon EventBridge rule to run the Automation document every hour.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The requirement is as soon as possible, so the trigger must be the configuration change trigger rather than a periodic one, which eliminates option A and points to the restricted-ssh rule on that trigger (C). Remediation must also be automatic rather than a report, which rules out option D's hourly Automation runs. Option B is wrong on two counts: it deletes all security group rules rather than only the offending SSH rule, which would break legitimate access, and it places a function and a rule in every account rather than using the organization's Config evaluation.

Security groups permitting SSH from 0.0.0.0/0 must be detected and remediated as soon as possible across all accounts in the organization. AWS Config is enabled in every account, a custom rule is created that runs on the restricted-ssh configuration change trigger so evaluation happens as soon as a security group changes rather than on a schedule, and the rule invokes an AWS Lambda function to remediate any noncompliant resource. Because the detection and the fix are both driven by Config's evaluation, the exposure is closed promptly without any scheduled job.

Using a periodic trigger with the vpc-sg-port-restriction-check rule (A) — phu0298 identified both problems, that the rule is not specific to the SSH-from-anywhere condition described, and that a periodic trigger does not provide real-time detection and delays remediation. phu0298 noted the same. Creating a Lambda in each account that deletes all security group rules, triggered by security group update or creation events (B) — this removes every rule rather than only the unrestricted SSH rule, which would disrupt all inbound access to every instance in the account, far exceeding the remediation required. Using a Systems Manager Automation document run every hour to inspect and delete noncompliant rules (D) — phu0298 and Slays both emphasized that the requirement is to act as soon as possible, and an hourly schedule leaves the exposure open for up to an hour after it appears.

Community Discussion (3 comments)

Srikantha 👍 1 Selected: C
Option C: AWS Config + real-time rule evaluation + Lambda remediation. This provides real-time security enforcement across all accounts.
Slays 👍 4 Selected: C
This option involves enabling AWS Config across all accounts, deploying the restricted-ssh rule, and setting up automatic remediation to address non-compliant security groups, thereby meeting the requirements efficiently.
phu0298 👍 4
C why not A: The vpe-sg-port-restriction-check AWS Config rule is not specific to this use case. The periodic trigger does not provide real-time detection, potentially delaying remediation.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is to detect and remediate unrestricted SSH access across all accounts as soon as possible. AWS Config provides continuous evaluation of resource configuration, and its configuration change trigger causes a rule to evaluate the moment a relevant resource such as a security group is modified, rather than waiting for a scheduled cycle (C). A custom rule is created using that trigger so that the evaluation happens immediately after any change to a security group, and the rule is configured to invoke an AWS Lambda function to remediate any noncompliant resource, which removes the offending rule automatically (C). Because Config is enabled in all accounts and is itself centrally governed, this gives organization-wide coverage with a single design, and the whole path from change to detection to remediation is event-driven, which satisfies the as soon as possible requirement. C is the correct answer.

Why the Other Options Are Wrong

A enables AWS Config for all accounts, uses a periodic trigger to activate the vpc-sg-port-restriction-check rule, and creates a Lambda function to remediate noncompliant rules. As phu0298 identified, this fails on two counts: the vpc-sg-port-restriction-check rule evaluates whether security groups restrict ports in general and is not specific to the SSH-from-0.0.0.0/0 condition described, and a periodic trigger does not provide real-time detection, so remediation can be delayed until the next evaluation cycle. That directly contradicts the as soon as possible requirement. B creates a Lambda function in each account to delete all security group rules, with an EventBridge rule matching security group update or creation events as the trigger. Deleting all rules rather than only the unrestricted SSH rule would strip every inbound rule from every security group in the account, breaking legitimate access to all workloads, which is a vastly destructive action for the stated problem; it also distributes a function into every account rather than relying on the organization's Config evaluation. D creates a Systems Manager Automation document in each account to inspect security groups and delete noncompliant rules, invoked by an EventBridge rule every hour. Both phu0298 and Slays stressed that the requirement is to act as soon as possible, and an hourly schedule leaves a security group exposing SSH to the internet for up to an hour after it appears, so this does not meet the requirement. C is correct.

Community Comment Notes

Community voted C unanimously. Srikantha characterized C as AWS Config plus real-time rule evaluation plus Lambda remediation, providing real-time security enforcement across all accounts. Slays explained that the option enables Config across all accounts, deploys the restricted-ssh rule, and sets up automatic remediation to address noncompliant security groups. phu0298 asked why not A and answered both objections precisely, that vpc-sg-port-restriction-check is not specific to this use case and that a periodic trigger delays remediation because it is not real-time. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide