What steps should the engineer take to meet this requirement with the LEAST administrative overhead?

1 Comment

  1. Raymond
    Author

    I deduce that the answer is:
    Use AWS Config. Identify all EC2 instances to be audited by enabling Config Recording on all Amazon EC2 resources for the region. Create a custom AWS Config rule that triggers an AWS Lambda function by using the “config-rule-change -triggered” blueprint. Modify the Lambda evaluateCompliance() function to verify host placement to return a NON_COMPLIANT result if the instance is not running on an EC2 Dedicated Host. Use the AWS Config report to address noncompliant instances.

Leave a Reply to Raymond Cancel reply

Your email address will not be published. Required fields are marked *

14 + 16 =