AWS Certified Solutions Architect Professional SAP-C02 Practice Question

Your organization has already turned on AWS Config recording in every AWS account and created an organization-wide aggregator in a delegated security account. The security engineers must now ensure that any security group that allows inbound SSH (TCP port 22) from 0.0.0.0/0 is detected and automatically remediated by deleting the rule. The solution must be centralized, avoid writing custom application code, and keep a detailed compliance history in AWS Config so that the team can verify every remediation. Which approach satisfies these requirements?

  • Use AWS Firewall Manager to create a security-group audit and enforcement policy that denies SSH from 0.0.0.0/0 and turn on automatic remediation across all accounts.

  • Enable Amazon GuardDuty in every member account and add an EventBridge rule in the security account that triggers a Lambda function to revoke any security-group rule that exposes port 22 to the internet.

  • Create an AWS Config organization managed rule named restricted-ssh and configure automatic remediation that invokes the AWS Systems Manager Automation runbook AWS-DisablePublicAccessForSecurityGroup by assuming a cross-account Automation role.

  • Activate the AWS Foundational Security Best Practices standard in AWS Security Hub and build a custom action that routes findings to a Step Functions workflow which calls Lambda to delete the non-compliant ingress rule.

AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot