A security engineer needs to receive email notifications whenever Amazon GuardDuty, AWS Identity and Access Management (IAM) Access Analyzer, or Amazon Macie generate a high-severity finding. The company uses AWS Control Tower for governance and has AWS Security Hub enabled with all service integrations. Which solution provides the required alerts with the least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an Amazon EventBridge rule that matches Security Hub findings with high severity. Configure the rule to publish to an Amazon Simple Notification Service (Amazon SNS) topic. Subscribe the required email addresses to the topic..
Why this is the answer
The correct solution leverages AWS Security Hub's aggregation capabilities. Since Security Hub is already enabled with all service integrations, it consolidates findings from GuardDuty, IAM Access Analyzer, and Macie. An Amazon EventBridge rule can then filter these consolidated findings for high severity and publish them to an Amazon SNS topic, which sends email notifications. This approach minimizes operational overhead by using existing integrations and managed services. Incorrect options: Creating separate Lambda functions for each service introduces significant operational overhead for development, deployment, and maintenance of multiple functions and schedules. AWS Control Tower events primarily relate to governance and account provisioning, not individual security findings from GuardDuty, IAM Access Analyzer, or Macie. This would not capture the required alerts. Hosting an application on Amazon EC2 adds substantial operational overhead for server management, patching, and scaling, which is unnecessary given the availability of managed services.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed