Firstly, we will try and understand the yellow triangle exclamation warning in my Security category. But how? There are two ways of doing so:
- You can select the alert from the Recommended Actions list, as shown in the previous screenshot.
- You can select the Security category icon showing the alert.
When selected, you can drill down into the check further to show the details captured. This shows my security alert:
Let's take a closer look at the information presented on this page:
- Firstly, it identifies the check that this alert was issued against, this being Security Groups - Specific Ports Unrestricted, which quite simply checks security groups for rules that allow unrestricted access (0.0.0.0/0) to specific ports.
- Alert Criteria defines the state at which this check is considered green, red, or yellow (its current state):
- Green: Access to port 80, 25, 443, or 465 is unrestricted.
- Red: Access to port 20, 21, 1433, 1434, 3306, 3389, 4333, 5432, or 5500...