A company wants a report listing security groups that permit RDP (TCP/3389) access from anywhere on the internet. Which AWS service should a SysOps admin use to obtain this information?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS Trusted Advisor to identify security groups that allow unrestricted access to port 3389..
Why this is the answer
AWS Trusted Advisor is the correct choice because its Security Checks include a specific check for "Security Groups - Unrestricted Access" to ports like 22 (SSH), 3389 (RDP), 2049 (NFS), 20 (FTP), 21 (FTP), and 23 (Telnet). This directly addresses the requirement to identify security groups allowing unrestricted RDP access. GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not for auditing security group configurations. SCPs are used to manage permissions for accounts in an organization, not to report on security group configurations. IAM Access Analyzer helps identify resources shared with external entities, focusing on access policies rather than security group rules for specific ports.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed