Topic 1 Question 275
A company needs to view a list of security groups that are open to the internet on port 3389.
What should a SysOps administrator do to meet this requirement?
Configure Amazon GuardDuty to scan security groups and report unrestricted access on port 3389.
Configure a service control policy (SCP) to identify security groups that allow unrestricted access on port 3389.
Use AWS Identity and Access Management Access Analyzer to find any instances that have unrestricted access on port 3389.
Use AWS Trusted Advisor to find security groups that allow unrestricted access on port 3389.
ユーザの投票
コメント(2)
- 正解だと思う選択肢: D
AWS Trusted Advisor is a service that provides best practice recommendations to help optimize your AWS environment. It can detect security-related issues, including security groups with overly permissive rules. In this case, it can help you identify security groups that are open to the internet on port 3389, which is the Remote Desktop Protocol (RDP) port.
By using AWS Trusted Advisor, the SysOps administrator can quickly access a list of security groups that have this unrestricted access configuration. This allows them to review and take necessary actions to tighten the security settings and restrict access as needed.
👍 4Christina6662023/07/25 - 正解だと思う選択肢: D👍 2rdiaz2023/06/18
シャッフルモード