A company has hundreds of AWS accounts in a single-Region AWS Organizations setup. A dedicated security tooling account is the delegated administrator for both Amazon GuardDuty and AWS Security Hub. GuardDuty and Security Hub are automatically enabled for all existing and new accounts. During control testing, the team launched an EC2 instance and issued DNS queries to example.com to trigger a GuardDuty DNS finding, but no finding appeared in the Security Hub delegated administrator account. What is the most likely reason the finding was not created?
Choose an answer
Tap an option to check your answer.
Correct answer: The VPC’s DHCP options set points to a custom OpenDNS resolver..
Why this is the answer
GuardDuty relies on DNS query logs to detect threats like DNS exfiltration. If the VPC's DHCP options set is configured to use a custom DNS resolver (like OpenDNS) instead of the Amazon-provided DNS, GuardDuty cannot inspect these DNS queries. Therefore, even if a malicious activity like querying example.com occurs, GuardDuty will not generate a finding. VPC Flow Logs are not strictly required for GuardDuty DNS findings; GuardDuty has its own data sources. The GuardDuty integration with Security Hub is managed by the delegated administrator, and the problem states GuardDuty and Security Hub are enabled, implying the integration. Cross-Region aggregation is irrelevant here as the setup is single-Region.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed