Answer: D
Both AWS Inspector & AWS Config can scan EC2 instances, access their network exposure, and then integrate with Amazon SNS to send notifications. Trusted Advisor also can check for overly permissive access of EC2 instances. Still, the notifications can be performed by monitoring the Trusted Advisor check results with AWS CloudWatch events that can use specific targets like Lambda, SNS etc.
Option A is incorrect. Trusted Advisor results cannot be directly configured with SNS. They need to be monitored using CloudWatch events.
Option B is incorrect. For the given scenario, both AWS Config & AWS Inspector can be configured to send notifications to SNS when a compliance breach is observed.
Option C is incorrect. The same explanation is given in Option
B.Option D is CORRECT. The Network Reachability rules package recently released for AWS Inspector helps analyze Amazon VPC network configuration to determine whether an EC2 instance can be reached from external networks like the Internet. It does it by analyzing network configurations like Security Groups, NACL’s, Route tables etc...The assessment that is run, its security findings can be published to an SNS topic.
AWS Config’s Configuration Streams can be configured with resources like Amazon SNS. Within AWS Config, you can configure Managed rules or Custom rules that can detect compliance violations & use the configuration stream for sending notifications.
Diagrams:
References:
https://aws.amazon.com/blogs/security/amazon-inspector-assess-network-exposure-ec2-instances-aws-network-reachability-assessments/
https://aws.amazon.com/blogs/security/how-to-remediate-amazon-inspector-security-findings-automatically/
https://aws.amazon.com/blogs/aws/trusted-advisor-console-basic/
https://docs.aws.amazon.com/awssupport/latest/user/cloudwatch-events-ta.html