A company has enabled Amazon GuardDuty in all AWS Regions. In one VPC, an EC2 instance functions as an FTP server and receives a high volume of connections from many client locations. GuardDuty flags this as a brute-force attack. The company marked the finding as a false positive, but GuardDuty continues to generate it. How can a security engineer reduce noise without sacrificing visibility into legitimate anomalies?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a GuardDuty suppression rule that automatically archives new findings matching specified criteria..
Why this is the answer
The correct answer is to create a GuardDuty suppression rule. This allows you to automatically archive findings that match specific criteria, such as the FTP server's IP address and the brute-force finding type, without disabling GuardDuty or losing visibility into other potential threats. This reduces noise while retaining the ability to review archived findings if needed. Disabling the FTP-related rule would remove all detection for FTP-related brute-force attacks, potentially missing legitimate threats. Adding the FTP server's IP to a trusted IP list is not a GuardDuty feature for suppressing specific finding types; trusted IP lists are primarily for whitelisting IPs that GuardDuty should ignore for certain network-based detections, not for suppressing specific finding types on an internal resource. Creating a Lambda function to delete findings is an inefficient and reactive approach that doesn't prevent the finding from being generated in the first place and could lead to missed legitimate alerts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed