A security engineer is building an incident response plan to detect suspicious activity for VPC-hosted resources across as many AWS Regions as possible in a cost-effective way. Which combination of steps will best meet these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Amazon GuardDuty in all AWS Regions., Create an Amazon Simple Notification Service (Amazon SNS) topic. Create an Amazon EventBridge rule that responds to GuardDuty findings and publishes them to the SNS topic..
Why this is the answer
Enabling Amazon GuardDuty in all AWS Regions is crucial because GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, providing broad coverage across multiple data sources like VPC Flow Logs, DNS logs, and CloudTrail management events. This offers a cost-effective way to detect suspicious activity across many regions without manually configuring individual logging services. Creating an Amazon SNS topic and an Amazon EventBridge rule that responds to GuardDuty findings and publishes them to the SNS topic provides an efficient and scalable mechanism for real-time notification and automated response to security incidents. This setup ensures that security teams are promptly alerted to threats detected by GuardDuty. Enabling VPC Flow Logs for all VPCs is a good practice but is a data source for GuardDuty, not a primary detection service itself. Enabling Amazon Detective in all AWS Regions is useful for investigation but not for initial detection. Creating an AWS Lambda function to publish findings to Amazon SES is more complex and less scalable for general notifications than using SNS with EventBridge.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed