Use configuration change recording with the ssh-restricted Config rule and SNS for notifications
A security team must record the configuration of AWS resources, detect issues, and send notifications for findings. The main workload in the AWS account consists of an Amazon EC2 Auto Scaling group that scales in and out several times during the day. The team wants to be notified within 2 days if any Amazon EC2 security group allows traffic on port 22 for 0.0.0.0/0. The team also needs a snapshot of the configuration of the AWS resources to be taken routinely. The security team has already created and subscribed to an Amazon Simple Notification Service (Amazon SNS) topic. Which solution meets these requirements?
Community Votes
82% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The correct managed rule is ssh-restricted, whose stated purpose is checking that security groups do not allow unrestricted access to port 22 (C). Configuration change recording is the appropriate recording mode for an Auto Scaling group that scales several times a day, because it captures each change as it happens, and it also produces the routine configuration snapshots the team requires. Option A pairs the wrong rule, vpc-sg-port-restriction-check, with periodic recording; option B pairs change recording with vpc-sg-open-only-to-authorized-ports, which evaluates whether ports are restricted to a set of authorized ports rather than specifically enforcing the SSH restriction; option D replaces the managed configuration service with custom Lambda code.
The environment scales in and out frequently, so recording must capture configuration changes as they occur rather than only on a periodic schedule, and the team wants routine configuration snapshots on top of that. The ssh-restricted AWS Config managed rule is the one that checks whether security groups allow unrestricted SSH access, so deploying it with configuration change recording and configuring AWS Config to publish to the SNS topic satisfies the detection and notification requirements.
Using the vpc-sg-port-restriction-check rule with periodic recording (A) — the rule is not the SSH-specific check the requirement names, and periodic recording can miss a noncompliant security group created and removed between snapshots, which matters in an environment that scales continuously. Using vpc-sg-open-only-to-authorized-ports (B) — this rule checks whether security groups restrict ports to a specified authorized list rather than specifically detecting unrestricted SSH; spring21 identified ssh-restricted as the rule that matches the port 22 from 0.0.0.0/0 condition. Writing a Lambda scheduled daily (D) — this discards the managed rule evaluation and configuration recording that AWS Config provides, adding custom code for no benefit.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement names a specific control: an EC2 security group must not allow traffic on port 22 from 0.0.0.0/0. The AWS Config managed rule that implements exactly this check is ssh-restricted, whose documentation states it checks that security groups do not allow unrestricted access to port 22, so deploying that rule addresses the detection requirement (C). Because the main workload is an Auto Scaling group that scales in and out several times a day, configuration change recording is the correct recording mode: it captures each configuration change as it occurs so a noncompliant security group is detected whether it persists or is short-lived, and it also yields the routine configuration snapshots the team wants. Configuring AWS Config to use the existing SNS topic as the notification target delivers findings to the subscribed security team within the required window (C).Why the Other Options Are Wrong
A deploys the vpc-sg-port-restriction-check rule with periodic recording. That rule is not the SSH-specific check the requirement calls for, and periodic recording only samples configuration on a schedule, so in an environment that scales continuously a noncompliant security group could appear and disappear between snapshots and never be recorded. B deploys vpc-sg-open-only-to-authorized-ports, which evaluates whether a security group restricts traffic to a specified list of authorized ports rather than specifically enforcing the unrestricted SSH condition; as spring21 noted, ssh-restricted is the rule that matches the port 22 from 0.0.0.0/0 requirement. matt200 questioned why B is wrong and the answer is this mismatch between the rule's purpose and the stated control. D creates a Lambda that evaluates security groups and publishes to SNS on a daily EventBridge schedule, replacing the managed rule and configuration recording with custom code that must be maintained and that only samples once a day. C is the correct answer.Community Comment Notes
Community voted C (78), with A a 17 percent minority. Srikantha and spring21 both identified ssh-restricted as the managed rule that checks security groups for unrestricted SSH access, and Srikantha noted that configuration change recording suits a dynamic environment like an Auto Scaling group. CHRIS12722222 favored A on the basis that periodic or daily recording might be preferable, but periodic recording can miss short-lived noncompliant resources and the rule in A is not the SSH-specific check. matt200's question about option B is answered by the rule-purpose mismatch described above.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →