A production AWS account receives an Amazon GuardDuty finding of type Impact:IAMUser/AnomalousBehavior. A security engineer must execute the investigation playbook and collect analysis without impacting the application. Which option provides the fastest path to meet this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Sign in with read-only credentials. Review the GuardDuty finding to determine which API calls triggered it. Use Amazon Detective to analyze those API calls in context..
Why this is the answer
The correct option allows for rapid investigation without disrupting the application. Signing in with read-only credentials ensures no accidental changes are made. Reviewing the GuardDuty finding for specific API calls provides the necessary context for analysis. Amazon Detective is purpose-built for security investigations, automatically analyzing and visualizing security data from GuardDuty, CloudTrail, and VPC Flow Logs, making it the fastest tool to understand the scope and impact of anomalous behavior. Attaching a DenyAll policy (options 1 and 3) would immediately impact the application by blocking the principal, which goes against the requirement to avoid impact. While using administrator credentials (option 3) would allow this action, it's a higher risk and still violates the non-impact requirement. CloudTrail Insights and CloudTrail Lake (option 4) are valuable for analysis but require more manual effort to correlate and visualize data compared to Detective's automated capabilities for this specific use case, making it a slower path.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed