QuestionQ52

Security and Compliance

A company uses one AWS account to operate hundreds of Amazon EC2 instances in a single AWS Region. New EC2 instances are launched and terminated hourly in the account. The account also contains existing EC2 instances that have been running for more than a week.

The company security policy requires every running EC2 instance to use an EC2 instance profile. If an EC2 instance has no instance profile attached, it must use a default instance profile with no IAM permissions assigned.

A DevOps engineer reviews the account and finds EC2 instances running without an instance profile. During the review, the DevOps engineer also notices that new EC2 instances are launched without an instance profile.

Which solution will ensure that an instance profile is attached to every existing and future EC2 instance in the Region?

Explanation

The AWS Config managed rule ec2-instance-profile-attached checks whether an EC2 instance has an IAM instance profile and reports instances without one as noncompliant. It is triggered by configuration changes, so it evaluates newly launched instances as well as the existing EC2 resources evaluated by AWS Config. Automatic remediation can invoke an AWS Systems Manager Automation runbook to associate the default instance profile, satisfying the requirement for both existing and future instances.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!