Courseiva
Network Security, Compliance and GovernancehardMultiple SelectObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

Which THREE actions can AWS Config perform to help with network security compliance? (Choose 3)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Evaluate whether security groups allow unrestricted SSH access

AWS Config can evaluate whether security groups allow unrestricted SSH access using managed rules like 'restricted-ssh'. Option C is correct because Config records configuration changes to Network ACLs and security groups, enabling tracking. Option D is correct because Config can trigger custom rules or send notifications via Amazon SNS when a security group rule is modified. Option B is incorrect because Config does not block traffic; it only evaluates and can trigger remediation actions via other services. Option E is incorrect because Config evaluates resources after creation; it cannot prevent creation, though it can trigger automated remediation via Lambda or Systems Manager.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Evaluate whether security groups allow unrestricted SSH access

    Why this is correct

    Config rules can check for specific security group rules.

  • Automatically block non-compliant traffic

    Why it's wrong here

    Config does not block traffic; it only evaluates and can trigger remediation actions.

  • Track changes to Network ACLs and security groups

    Why this is correct

    Config records configuration changes to these resources.

  • Send alerts when a security group rule is modified

    Why this is correct

    Config can trigger SNS notifications on configuration changes.

  • Prevent creation of VPCs that do not have a specific tag

    Why it's wrong here

    Config does not prevent creation; it can evaluate after creation.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.