A penetration tester performed internal port scans against the company's EC2 instances and the scans went undetected. The company wants automatic notification when port scans are detected. They have created and subscribed to an SNS topic. What should they do next to get port scan notifications?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Amazon GuardDuty, create a CloudWatch alarm for EC2 and port-scan findings, and connect that alarm to the SNS topic..
Why this is the answer
Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads. It specifically detects port scans and other network-based threats. GuardDuty findings can be sent to Amazon CloudWatch Events, which can then trigger a CloudWatch alarm based on specific finding types (like port scans against EC2 instances). This alarm can then publish to an SNS topic for notifications. Amazon Inspector is a vulnerability management service that assesses EC2 instances for vulnerabilities and deviations from best practices, but it doesn't primarily detect real-time port scans. While it can identify open ports as part of its assessment, it's not designed for active threat detection like GuardDuty. AWS CloudTrail logs API activity, not network traffic directly, making it unsuitable for real-time port scan detection.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed