Which AWS service can detect security groups that are misconfigured and allowing unrestricted access to specific ports?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS Trusted Advisor.
Why this is the answer
AWS Trusted Advisor is the correct answer because it provides recommendations across five categories, including security. Specifically, it has checks that identify security groups with unrestricted access (0.0.0.0/0) to ports like 22 (SSH), 3389 (RDP), and 20, 21 (FTP), which are common misconfigurations. Amazon CloudWatch is a monitoring service for resources and applications, not a security configuration checker. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, but it doesn't proactively identify misconfigured security groups in the same way Trusted Advisor does. AWS Health Dashboard provides personalized views of AWS service health and alerts, not security configuration analysis.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed