I think it can be two answers for this questiosn

Which Amazon Inspector rules package would you use to check for instances which enable root login over SSH?

the right answer is Security best practice but the CIS would also flag up root having SSH access

That’s very insightful, and you’re not the first one to flag this with us. We’re in the process of pushing out a new update to this quiz, which includes an update to address this particular issue. Hopefully it should be available for everyone soon. Thanks for your thoughts on this!

Feedback can also be submitted directly to us through our Contact Support form, where one of our technical team members will respond and assess what we need to do to update our content

