Question 1
Q1A company hosts an internal application on Amazon EC2 instances. All application data and requests route through an AWS Site-to-Site VPN connection between the on-premises network and AWS. The company must monitor the application for changes that allow network access outside of the corporate network. Any change that exposes the application externally must be restricted automatically.
Which solution meets these requirements in the MOST operationally efficient manner?
Show answer & explanation
Correct answer: A
Lambda functions can automatically remediate security group changes by removing non-corporate CIDR ranges when triggered by VPC Flow Logs anomalies through CloudWatch alarms. This provides automated response to unauthorized network access attempts. AWS Config provides compliance monitoring but not automated remediation, and Systems Manager scheduling lacks real-time detection capabilities.