A company uses one AWS account to test applications on Amazon EC2 instances. AWS Config is enabled in the account, and the restricted-ssh AWS Config managed rule is active.
The company requires an automated monitoring solution that provides a customized, real-time notification whenever any security group in the account is noncompliant with the restricted-ssh rule. The customized notification must include the name and ID of the noncompliant security group.
A DevOps engineer creates an Amazon Simple Notification Service (Amazon SNS) topic in the account and subscribes the appropriate personnel to that topic.
What should the DevOps engineer do next to satisfy these requirements?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion