Use configuration change recording with the ssh-restricted Config rule and SNS for notifications

Answer Correct answer: C — enable configuration change recording, deploy the ssh-restricted Config rule, and notify through the SNS topic.

A security team must record the configuration of AWS resources, detect issues, and send notifications for findings. The main workload in the AWS account consists of an Amazon EC2 Auto Scaling group that scales in and out several times during the day. The team wants to be notified within 2 days if any Amazon EC2 security group allows traffic on port 22 for 0.0.0.0/0. The team also needs a snapshot of the configuration of the AWS resources to be taken routinely. The security team has already created and subscribed to an Amazon Simple Notification Service (Amazon SNS) topic. Which solution meets these requirements?

  1. Configure AWS Config to use periodic recording for the AWS account. Deploy the vpc-sg-port-restriction-check AWS Config managed rule. Configure AWS Config to use the SNS topic as the target for notifications.
  2. Configure AWS Config to use configuration change recording for the AWS account. Deploy the vpc-sg-open-only-to-authorized-ports AWS Config managed rule. Configure AWS Config to use the SNS topic as the target for notifications.
  3. Configure AWS Config to use configuration change recording for the AWS account. Deploy the ssh-restricted AWS Config managed rule. Configure AWS Config to use the SNS topic as the target for notifications. Correct Answer
  4. Create an AWS Lambda function to evaluate security groups and publish a message to the SNS topic. Use an Amazon EventBridge rule to schedule the Lambda function to run once a day.

Community Votes

C
82%
A
18%

82% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The correct managed rule is ssh-restricted, whose stated purpose is checking that security groups do not allow unrestricted access to port 22 (C). Configuration change recording is the appropriate recording mode for an Auto Scaling group that scales several times a day, because it captures each change as it happens, and it also produces the routine configuration snapshots the team requires. Option A pairs the wrong rule, vpc-sg-port-restriction-check, with periodic recording; option B pairs change recording with vpc-sg-open-only-to-authorized-ports, which evaluates whether ports are restricted to a set of authorized ports rather than specifically enforcing the SSH restriction; option D replaces the managed configuration service with custom Lambda code.

The environment scales in and out frequently, so recording must capture configuration changes as they occur rather than only on a periodic schedule, and the team wants routine configuration snapshots on top of that. The ssh-restricted AWS Config managed rule is the one that checks whether security groups allow unrestricted SSH access, so deploying it with configuration change recording and configuring AWS Config to publish to the SNS topic satisfies the detection and notification requirements.

Using the vpc-sg-port-restriction-check rule with periodic recording (A) — the rule is not the SSH-specific check the requirement names, and periodic recording can miss a noncompliant security group created and removed between snapshots, which matters in an environment that scales continuously. Using vpc-sg-open-only-to-authorized-ports (B) — this rule checks whether security groups restrict ports to a specified authorized list rather than specifically detecting unrestricted SSH; spring21 identified ssh-restricted as the rule that matches the port 22 from 0.0.0.0/0 condition. Writing a Lambda scheduled daily (D) — this discards the managed rule evaluation and configuration recording that AWS Config provides, adding custom code for no benefit.

Community Discussion (8 comments)

Srikantha 👍 1 Selected: C
AWS Config with configuration change recording ensures that every time a resource configuration changes, it's recorded—ideal for dynamic environments like Auto Scaling groups. The ssh-restricted managed rule specifically checks whether port 22 (SSH) is open to 0.0.0.0/0, which directly satisfies the requirement. Configuring AWS Config to publish to an existing SNS topic ensures the security team is notified of any findings within 2 days or sooner, depending on when the change occurs.
jojewi8143 👍 2 Selected: C
ssh-restricted
matt200 👍 1 Selected: B
Why not B? https://docs.aws.amazon.com/config/latest/developerguide/vpc-sg-open-only-to-authorized-ports.html
CHRIS12722222 👍 1 Selected: A
i think we need to use periodic or daily recording instead of continuous one
spring21 👍 4 Selected: C
For monitoring if any EC2 security group allows traffic on port 22 (SSH) from 0.0.0.0/0: Use the managed AWS Config rule: restricted-ssh This rule checks that security groups do not allow unrestricted incoming SSH traffic (port 22) from 0.0.0.0/0.
eugene2owl 👍 2 Selected: A
"A" because "vpc-sg-port-restriction-check" fits requested check well, and the condition says "... to be taken routinely", which means "periodically", "regularly". "B" and "C" propose running "on-change" instead, which does not fit condition "routinely"
f4b18ba 👍 4 Selected: C
Configuration Change Recording: By configuring AWS Config to use configuration change recording, the system will continuously monitor and record configurations of your AWS resources whenever there are changes. This ensures real-time compliance monitoring and reduces the delay in detection. Appropriate Managed Rule: The ssh-restricted AWS Config managed rule specifically checks for security groups that allow unrestricted SSH (port 22) access. This rule directly addresses the requirement to be notified if any EC2 security group allows traffic on port 22 for 0.0.0.0/0. Notification Setup: Configuring AWS Config to use the SNS topic ensures that the security team will be notified within the specified time frame if the rule is violated. AWS Config can send notifications to the SNS topic as soon as a non-compliant resource is detected.
uncledana 👍 3 Selected: C
The correct answer is C

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement names a specific control: an EC2 security group must not allow traffic on port 22 from 0.0.0.0/0. The AWS Config managed rule that implements exactly this check is ssh-restricted, whose documentation states it checks that security groups do not allow unrestricted access to port 22, so deploying that rule addresses the detection requirement (C). Because the main workload is an Auto Scaling group that scales in and out several times a day, configuration change recording is the correct recording mode: it captures each configuration change as it occurs so a noncompliant security group is detected whether it persists or is short-lived, and it also yields the routine configuration snapshots the team wants. Configuring AWS Config to use the existing SNS topic as the notification target delivers findings to the subscribed security team within the required window (C).

Why the Other Options Are Wrong

A deploys the vpc-sg-port-restriction-check rule with periodic recording. That rule is not the SSH-specific check the requirement calls for, and periodic recording only samples configuration on a schedule, so in an environment that scales continuously a noncompliant security group could appear and disappear between snapshots and never be recorded. B deploys vpc-sg-open-only-to-authorized-ports, which evaluates whether a security group restricts traffic to a specified list of authorized ports rather than specifically enforcing the unrestricted SSH condition; as spring21 noted, ssh-restricted is the rule that matches the port 22 from 0.0.0.0/0 requirement. matt200 questioned why B is wrong and the answer is this mismatch between the rule's purpose and the stated control. D creates a Lambda that evaluates security groups and publishes to SNS on a daily EventBridge schedule, replacing the managed rule and configuration recording with custom code that must be maintained and that only samples once a day. C is the correct answer.

Community Comment Notes

Community voted C (78), with A a 17 percent minority. Srikantha and spring21 both identified ssh-restricted as the managed rule that checks security groups for unrestricted SSH access, and Srikantha noted that configuration change recording suits a dynamic environment like an Auto Scaling group. CHRIS12722222 favored A on the basis that periodic or daily recording might be preferable, but periodic recording can miss short-lived noncompliant resources and the rule in A is not the SSH-specific check. matt200's question about option B is answered by the rule-purpose mismatch described above.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide