An organization requires that all Amazon EC2 instances must be launched only with approved Amazon Machine Images (AMIs) that have been pre-approved by the security team. The SysOps administrator needs to enforce this policy for all current and future instances in the AWS account. Unapproved AMIs should be prevented from launching. Which solution meets these requirements with the least operational overhead?
Trap 1: Use AWS Config with the 'approved-amis-by-id' managed rule to…
AWS Config detects noncompliant instances after launch. While automatic remediation can terminate them, it does not prevent the launch, so it does not fully meet the requirement.
Trap 2: Create an IAM policy that denies ec2:RunInstances for any AMI not…
Applying IAM policies requires manual updates to the policy document every time a new AMI is approved, creating significant operational overhead for future instances. This approach fails because it lacks the automated enforcement provided by AWS Organizations Service Control Policies or SCPs across an entire account. While this method works for restricting specific users from launching certain resource types in a single-account setup, it does not scale to enforce global guardrails without constant administrative intervention.
Trap 3: Use AWS Systems Manager Patch Manager to approve AMIs and configure…
AWS Systems Manager Patch Manager is for patching operating systems, not for controlling which AMIs can be launched. It does not prevent unapproved AMI launches.
- A
Use AWS Config with the 'approved-amis-by-id' managed rule to evaluate and automatically remediate noncompliant instances.
Why it fails: AWS Config detects noncompliant instances after launch. While automatic remediation can terminate them, it does not prevent the launch, so it does not fully meet the requirement.
- B
Use an AWS Service Control Policy (SCP) to deny ec2:RunInstances if the AMI ID is not in an approved list.
Correct. An SCP denies ec2:RunInstances for unapproved AMIs, preventing any launch across the entire account with minimal operational overhead.
- C
Create an IAM policy that denies ec2:RunInstances for any AMI not on an approved list and attach it to all IAM users and roles.
Why it fails: Applying IAM policies requires manual updates to the policy document every time a new AMI is approved, creating significant operational overhead for future instances. This approach fails because it lacks the automated enforcement provided by AWS Organizations Service Control Policies or SCPs across an entire account. While this method works for restricting specific users from launching certain resource types in a single-account setup, it does not scale to enforce global guardrails without constant administrative intervention.
- D
Use AWS Systems Manager Patch Manager to approve AMIs and configure the fleet to use only approved images.
Why it fails: AWS Systems Manager Patch Manager is for patching operating systems, not for controlling which AMIs can be launched. It does not prevent unapproved AMI launches.