DOP-C02 Incident and Event Response Practice Question
Exhibit
Refer to the exhibit.
# CloudTrail log entry (JSON)
{
"eventVersion": "1.08",
"userIdentity": {
"type": "IAMUser",
"arn": "arn:aws:iam::123456789012:user/admin",
"accountId": "123456789012"
},
"eventTime": "2024-02-15T10:00:00Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "AuthorizeSecurityGroupIngress",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.5",
"requestParameters": {
"groupId": "sg-12345678",
"ipPermissions": {
"items": [
{
"ipProtocol": "tcp",
"fromPort": 22,
"toPort": 22,
"ipRanges": {
"items": [
{
"cidrIp": "0.0.0.0/0"
}
]
}
}
]
}
}
}A security engineer reviews the CloudTrail log entry above and notices that a security group was modified to allow SSH access from anywhere. The engineer wants to ensure that such changes are automatically detected and remediated in the future. What should the engineer do?
⚠ Common exam trap
It's easy for candidates to confuse detection-only services (like CloudWatch alarms or GuardDuty) with services that can also perform automated remediation (like AWS Config with Systems Manager Automation), leading them to choose options that only alert but do not fix the issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an AWS Config rule that checks security group rules and triggers an AWS Systems Manager Automation document to revoke the ingress rule.
AWS Config can continuously evaluate security group rules against a custom or managed rule (e.g., restricted-ssh) and, upon detecting a noncompliant rule allowing 0.0.0.0/0 on port 22, trigger an AWS Systems Manager Automation document that automatically revokes the offending ingress rule. This provides both detection and remediation without manual intervention, meeting the requirement for automated detection and remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure CloudTrail to send logs to CloudWatch Logs and create a metric filter that alerts on AuthorizeSecurityGroupIngress events with 0.0.0.0/0.
Why it's wrong here
This approach is detective only. CloudTrail logs the AuthorizeSecurityGroupIngress API call, and a CloudWatch Logs metric filter can raise an alarm when the request contains an IPv4 CIDR of 0.0.0.0/0, but the filter cannot automatically undo the rule. Without a separate remediation workflow (such as an AWS Config rule invoking Systems Manager Automation), the insecure rule remains in effect until an engineer manually intervenes. Thus it fails to satisfy the requirement for automatic remediation.
- ✗
Create an IAM policy that denies the ec2:AuthorizeSecurityGroupIngress action if the source IP is 0.0.0.0/0.
Why it's wrong here
IAM policies evaluate the identity of the API caller and the requested action, not the contents of the security group rule being created. You cannot condition on the destination CIDR block inside the ec2:AuthorizeSecurityGroupIngress request, because no request parameter key exposes the rule's IP range to IAM. The aws:SourceIp condition key reflects the caller's network IP, not the security group rule's source, so this policy would incorrectly deny legitimate users based on their location and still allow all-IP ingress. Therefore it cannot prevent or undo the permissive rule.
- ✓
Create an AWS Config rule that checks security group rules and triggers an AWS Systems Manager Automation document to revoke the ingress rule.
Why this is correct
This is the only option that provides automatic detection and remediation. An AWS Config managed or custom rule can evaluate each security group and mark it NON_COMPLIANT if it contains an ingress rule with 0.0.0.0/0. You can attach that rule to a Systems Manager Automation document, which uses aws:executeAwsApi to call RevokeSecurityGroupIngress and remove the offending rule, or trigger an AWS Lambda function; this remediation runs automatically on each configuration change. Thus it directly satisfies the requirement to revert unauthorized changes.
- ✗
Enable Amazon GuardDuty to detect and block such changes in real time.
Why it's wrong here
GuardDuty is an intelligent threat detection service that reviews VPC flow logs, DNS query logs, and CloudTrail management events to produce security findings. It does not modify security groups or block configuration changes, and there is no GuardDuty feature that revokes an ingress rule. While GuardDuty might flag a compromised instance attempting unusual traffic, it would not act on a permissive security group rule added by an identity. This misunderstands the service's scope.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.