QuestionQ16

Security and Compliance

A company runs an FTP server on Amazon EC2 instances. In the company’s AWS environment, AWS Security Hub sends findings about the EC2 instances to Amazon EventBridge because the FTP port has become publicly exposed in the security groups attached to the instances.

A CloudOps engineer needs an automated solution to remediate the Security Hub finding and any similar findings for exposed ports. The CloudOps engineer wants to use an event-driven approach.

Which solution meets these requirements?

Explanation

AWS Security Hub sends findings to EventBridge in near real time, and EventBridge rules can invoke AWS Lambda functions for automated remediation. A Lambda function can revoke the inbound security group rule that permits public access, eliminating the exposed-port condition while applying the same event-driven remediation pattern to similar findings.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!