ANS-C01 Network Security, Compliance and Governance Practice Question
Which THREE actions can AWS Config perform to help with network security compliance? (Choose 3)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evaluate whether security groups allow unrestricted SSH access
AWS Config can evaluate whether security groups allow unrestricted SSH access using managed rules like 'restricted-ssh'. Option C is correct because Config records configuration changes to Network ACLs and security groups, enabling tracking. Option D is correct because Config can trigger custom rules or send notifications via Amazon SNS when a security group rule is modified. Option B is incorrect because Config does not block traffic; it only evaluates and can trigger remediation actions via other services. Option E is incorrect because Config evaluates resources after creation; it cannot prevent creation, though it can trigger automated remediation via Lambda or Systems Manager.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Evaluate whether security groups allow unrestricted SSH access
Why this is correct
Config rules can check for specific security group rules.
- ✗
Automatically block non-compliant traffic
Why it's wrong here
Config does not block traffic; it only evaluates and can trigger remediation actions.
- ✓
Track changes to Network ACLs and security groups
Why this is correct
Config records configuration changes to these resources.
- ✓
Send alerts when a security group rule is modified
Why this is correct
Config can trigger SNS notifications on configuration changes.
- ✗
Prevent creation of VPCs that do not have a specific tag
Why it's wrong here
Config does not prevent creation; it can evaluate after creation.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.