The company runs applications in AWS accounts that are members of an AWS Organizations organization. Those applications use Amazon EC2 and Amazon S3. The company wants to detect compromised EC2 instances, suspicious network behavior, and unusual API calls across current and future accounts. When such events are detected, the company wants to publish a notification to an existing Amazon SNS topic used by its operations team. Which approach meets these requirements and follows AWS best practices?
Choose an answer
Tap an option to check your answer.
Correct answer: In the organization’s management account, designate an AWS account as the Amazon GuardDuty administrator. From the GuardDuty administrator account, invite the company’s existing AWS accounts as member accounts in GuardDuty. In the GuardDuty administrator account, create an Amazon EventBridge rule with an event pattern that matches GuardDuty findings and forwards matched events to the SNS topic..
Why this is the answer
The correct approach leverages GuardDuty's multi-account management capabilities. Designating an administrator account allows centralized management and viewing of findings from all member accounts. GuardDuty directly detects compromised EC2 instances, suspicious network behavior, and unusual API calls. Creating an EventBridge rule in the administrator account to match GuardDuty findings and forward them to an SNS topic provides a single point of notification for all organizational accounts, fulfilling the requirements efficiently. The other options are less optimal: The second option involves manual invitations and a complex StackSet deployment, which is less straightforward than GuardDuty's built-in organization integration. The third and fourth options focus on CloudTrail, VPC Flow Logs, and Security Hub. While these are valuable security services, they don't directly address the core requirement of detecting "compromised EC2 instances, suspicious network behavior, and unusual API calls" as comprehensively and directly as GuardDuty does. Security Hub aggregates findings but doesn't generate them itself for these specific threats in the same way GuardDuty does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed