How can this task be automated?

1 Comment

  1. Ronald
    Author

    I judge that the answer is:
    Attach an IAM policy to the developers’ IAM group to deny associate-address permissions. Create a custom AWS Config rule to check whether an Elastic IP address is associated with any instance tagged as production, and alert the security team.

Leave a Reply

Your email address will not be published. Required fields are marked *

17 − one =