QuestionQ15

Security and Compliance

A company security policy requires that incoming SSH traffic be limited to a defined set of addresses. The company uses an AWS Config rule to determine whether security groups permit unrestricted incoming SSH traffic.

A CloudOps engineer identifies a noncompliant resource and manually corrects the security group. The CloudOps engineer wants to automate remediation for other noncompliant resources.

What is the MOST operationally efficient solution that fulfills these requirements?

Explanation

AWS Config can automatically remediate resources that its rules mark noncompliant by invoking an associated Systems Manager Automation remediation action. The AWS-managed AWS-DisableIncomingSSHOnPort22 runbook removes unrestricted inbound SSH rules on TCP port 22 from security groups, directly enforcing the policy without custom Lambda code or separate CloudWatch/EventBridge automation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!