A company uses AWS CloudFormation to deploy infrastructure. The security team requires that all security groups restrict SSH access to only the company's VPN public IP address range (203.0.113.0/24). A developer creates a stack that includes a security group with SSH open to 0.0.0.0/0. The stack deploys successfully. Which action should the security team take to prevent this in the future?
AWS Config can evaluate security group rules and trigger remediation via Systems Manager Automation.
Why this answer
Using AWS CloudFormation Stack Policies allows you to define which stack resources can be updated or deleted, but not to enforce security rules. AWS Config rules can evaluate resources against desired configurations and trigger remediation or notifications. Service control policies (SCPs) are for AWS Organizations and cannot block resource creation at the account level.
IAM permissions can prevent users from creating security groups with open SSH, but that requires careful management and does not cover all cases. Option B is the correct answer because an AWS Config managed rule can detect security groups with unrestricted SSH access and trigger an automatic remediation action via AWS Systems Manager Automation.