Amazon
SOA-C02 · Question #375
A company has a compliance requirement that no security groups can allow SSH ports to be open to all IP addresses. A SysOps administrator must implement a solution that will notify the company's SysOp
The correct answer is C. Activate the AWS Config restricted-ssh managed rule. Add automatic remediation to the AWS. https://docs.aws.amazon.com/config/latest/developerguide/restricted-ssh.html
Submitted by tunde_lagos· Mar 30, 2026Security and Compliance
Question
A company has a compliance requirement that no security groups can allow SSH ports to be open to all IP addresses. A SysOps administrator must implement a solution that will notify the company's SysOps team when a security group rule violates this requirement. The solution also must remediate the security group rule automatically. Which solution will meet these requirements?
Options
- ACreate an Amazon EventBridge (Amazon CloudWatch Events) rule that invokes an AWS Lambda
- BCreate an AWS CloudTrail metric filter for security group changes. Create an Amazon
- CActivate the AWS Config restricted-ssh managed rule. Add automatic remediation to the AWS
- DCreate an AWS CloudTrail metric filter for security group changes. Create an Amazon
How the community answered
(60 responses)- A3% (2)
- B8% (5)
- C72% (43)
- D17% (10)
Explanation
https://docs.aws.amazon.com/config/latest/developerguide/restricted-ssh.html
Topics
#AWS Config managed rules#security group compliance#auto-remediation#SSH port restriction
Community Discussion
No community discussion yet for this question.