exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 670 discussion

Exam question from Amazon's AWS-SysOps
Question #: 670
Topic #: 1
[All AWS-SysOps Questions]

The Security team has decided that there will be no public internet access to HTTP (TCP port 80) because it is moving to HTTPS for all incoming web traffic. The team has asked a SysOps Administrator to provide a report on any security groups that are not compliant.
What should the SysOps Administrator do to provide near real-time compliance reporting?

  • A. Enable AWS Trusted Advisor and show the Security team that the Security Groups unrestricted access check will alarm.
  • B. Schedule an AWS Lambda function to run hourly to scan and evaluate all security groups, and send a report to the Security team.
  • C. Use AWS Config to enable the restricted-common-ports rule, and add port 80 to the parameters.
  • D. Use Amazon Inspector to evaluate the security groups during scans, and send the completed reports to the Security team.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
saumenP
Highly Voted 2 years, 7 months ago
C could be correct While both trusted advisor and AWS config can audit security groups, AWS config provides near real-time compliance report. With trusted advisor, you can setup weekly email notification for recommendations.
upvoted 19 times
...
gretch
Highly Voted 2 years, 6 months ago
C https://docs.aws.amazon.com/config/latest/developerguide/restricted-common-ports.html
upvoted 7 times
...
albert_kuo
Most Recent 9 months, 3 weeks ago
Selected Answer: C
AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources. By leveraging AWS Config, you can continuously monitor and report on compliance with specified rules, including security group configurations.
upvoted 1 times
...
gulu73
1 year, 3 months ago
Selected Answer: C
C is the answer.
upvoted 1 times
...
RicardoD
2 years, 6 months ago
C is the answer Use config rules to monitor and generate reports
upvoted 2 times
...
sasquatchshrimp
2 years, 6 months ago
I am going with C: https://aws.amazon.com/blogs/security/amazon-inspector-assess-network-exposure-ec2-instances-aws-network-reachability-assessments/
upvoted 1 times
...
Lionnaire
2 years, 6 months ago
I'll go with C. https://docs.amazonaws.cn/en_us/config/latest/developerguide/restricted-common-ports.html
upvoted 1 times
...
JohnO1971
2 years, 6 months ago
https://docs.aws.amazon.com/config/latest/developerguide/restricted-common-ports.html
upvoted 1 times
...
abhishek_m_86
2 years, 6 months ago
C. Use AWS Config to enable the restricted-common-ports rule, and add port 80 to the parameters. Seem correct
upvoted 1 times
...
Tillerman
2 years, 6 months ago
Can it be D as it requiring real time compliance reports?
upvoted 2 times
...
rootkim
2 years, 6 months ago
C is the right answer. A cannot be the answer. 1) TA cannot verify unrestricted access to port 80. Check security group rules except ports 22, 80, and 443 2) TA provides weekly notifications, but not real time.
upvoted 1 times
...
areke
2 years, 6 months ago
The Answer is A: Amazon Trusted Advisor for certain. If the question was referring to security vulnerability and generating assessment reports, then that will be Amazon Inspector.
upvoted 1 times
...
jackdryan
2 years, 6 months ago
I'll go with C
upvoted 1 times
...
MFDOOM
2 years, 6 months ago
C. Use AWS Config to enable the restricted-common-ports rule, and add port 80 to the parameters.
upvoted 1 times
MFDOOM
2 years, 6 months ago
Keyword here is "compliance"
upvoted 1 times
...
...
r_man
2 years, 6 months ago
Use Amazon Inspector to evaluate the security groups during scans, and send the completed reports to the Security team.
upvoted 1 times
...
vnsuk
2 years, 6 months ago
i was wrong, inspector on works wth ec2 instances. Config is correct.
upvoted 1 times
...
vnsuk
2 years, 6 months ago
config does not generate report, inspector is for checks and compliance to configurations.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago