Question 494:
You are a DevOps engineer working in a big organization and you manage AWS resources including EC2 and RDS. One day, the security group of an EC2 bastion host has been modified to allow the inbound SSH traffic from any IP addresses. You notice this potential security risk after several days. Although this issue did not lead to any data leakage, you still want to enhance the AWS configurations so that whenever the IP addresses of the incoming SSH traffic in the security groups are not restricted, you will get a notification in time. Which option is the most suitable?
Answer options:
A.Create an AWS Config rule and select the AWS Managed rule "restricted-ssh" to check whether security groups disallow unrestricted incoming SSH traffic. B.Add a rule in AWS Config and select the AWS Managed rule "restricted-common-ports" to check whether security groups disallow unrestricted incoming SSH traffic. C.Enable Amazon Inspector and include the rule package "Common Vulnerabilities and Exposures-1.1" to check the security groups. Configure a notification through SNS. D.Enable Amazon GuardDuty and check the security findings of security groups in AWS Security Hub.