An application running on EC2 instances in an Auto Scaling group behind an Application Load Balancer became unavailable after a security group change. A network engineer must implement a mechanism that automatically remediates noncompliant security group changes to prevent this downtime from recurring. Which solution satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an AWS Config rule to detect differences between the desired security group configuration and the current configuration. Create an AWS Systems Manager Automation runbook to remediate noncompliant security groups..
Why this is the answer
The correct solution involves using AWS Config and AWS Systems Manager Automation. AWS Config is ideal for continuously monitoring and recording AWS resource configurations, such as security groups, and evaluating them against desired configurations using rules. When a noncompliant change is detected, AWS Config can trigger an AWS Systems Manager Automation runbook. This runbook can then execute predefined actions to revert the security group to its compliant state, providing automated remediation. GuardDuty is a threat detection service, not a configuration compliance service, so it cannot detect configuration drift. AWS OpsWorks for Chef is a configuration management service primarily for server automation and application deployment, not for automated remediation of security group changes triggered by compliance violations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed