Use an EventBridge rule on the Config compliance-change event to notify an SNS topic

Answer Correct answer: B — an EventBridge rule on the Config compliance-change event notifies an SNS topic in near real time.

A company has a requirement that no Amazon EC2 security group can allow SSH access from the CIDR block 0.0.0.0/0. The company wants to monitor compliance with this requirement at all times and wants to receive a near-real-time notification if any security group is noncompliant. A security engineer has configured AWS Config and will use the restricted-ssh managed rule to monitor the security groups. What should the security engineer do next to meet these requirements?

  1. Configure AWS Config to send its configuration snapshots to an Amazon S3 bucket. Create an AWS Lambda function to run on a PutEvent to the S3 bucket. Configure the Lambda function to parse the snapshot for a compliance change to the restricted-ssh managed rule. Configure the Lambda function to send a notification to an Amazon Simple Notification Service (Amazon SNS) topic if a change is discovered.
  2. Configure an Amazon EventBridge event rule that is invoked by a compliance change event from AWS Config for the restricted-ssh managed rule. Configure the event rule to target an Amazon Simple Notification Service (Amazon SNS) topic that will provide a notification. Correct Answer
  3. Configure AWS Config to push all its compliance notifications to Amazon CloudWatch Logs. Configure a CloudWatch Logs metric filter on the AWS Config log group to look for a compliance notification change on the restricted-ssh managed rule. Create an Amazon CloudWatch alarm on the metric filter to send a notification to an Amazon Simple Notification Service (Amazon SNS) topic if the alarm is in the ALARM state.
  4. Configure an Amazon CloudWatch alarm on the CloudWatch metric for the restricted-ssh managed rule. Configure the CloudWatch alarm to send a notification to an Amazon Simple Notification Service (Amazon SNS) topic if the alarm is in the ALARM state.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

AWS Config emits compliance-change events to EventBridge; an EventBridge rule on that event → SNS gives near-real-time alerts with no custom code. The S3-snapshot + Lambda (A) and CloudWatch Logs metric-filter (C) approaches add polling/lag and extra components; a CloudWatch alarm on the Config metric (D) is less direct than the event-driven rule. B is most efficient and real-time.

To monitor the restricted-ssh Config rule continuously and get near-real-time notification when a security group becomes noncompliant, configure an Amazon EventBridge event rule triggered by the AWS Config compliance-change event for that rule, targeting an SNS topic. This is the native, near-real-time path without polling or custom Lambda.

Using S3 config snapshots + a Lambda on PutObject (A)—adds polling latency and custom code versus the event-driven rule. Using CloudWatch Logs metric filters + alarms (C)—more moving parts and not as direct as EventBridge. A CloudWatch alarm on the Config metric (D) is viable but less immediate than the compliance-change event rule. B is the cleanest.

Community Discussion (3 comments)

getadroit 👍 1
https://repost.aws/knowledge-center/config-resource-non-compliant
getadroit 👍 1
https://aws.amazon.com/blogs/mt/implement-aws-config-rule-remediation-with-systems-manager-change-manager/
rhsilva 👍 2 Selected: B
https://docs.aws.amazon.com/config/latest/developerguide/restricted-ssh.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Config continuously evaluates the restricted-ssh managed rule and emits a compliance-change event to EventBridge whenever a security group's compliance status flips. An EventBridge rule matching that event and targeting an SNS topic delivers a near-real-time notification with no polling or custom Lambda—exactly the monitoring-and-alert requirement.

Why the Other Options Are Wrong

A relies on Config snapshots delivered to S3 plus a Lambda on PutObject, adding latency and custom code. C uses CloudWatch Logs metric filters and alarms, more components and not as immediate. D uses a CloudWatch alarm on the Config metric, workable but less direct than the event-driven EventBridge rule. B is the most efficient.

Community Comment Notes

Community voted B (100). Commenters linked the AWS Config restricted-ssh rule and the EventBridge compliance-change pattern as the near-real-time notification mechanism. B confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide