Multiple Choice
A company is using AWS Organizations to manage multiple AWS member accounts. All of these accounts have Amazon GuardDuty enabled in all Regions. The company's AWS Security Operations Center has a centralized security account for logging and monitoring. One of the member accounts has received an excessively high bill. A security engineer discovers that a compromised Amazon EC2 instance is being used to mine cryptocurrency. The Security Operations Center did not receive a GuardDuty finding in the central security account, but there was a GuardDuty finding in the account containing the compromised EC2 instance. The security engineer needs to ensure all GuardDuty findings are available in the security account. What should the security engineer do to resolve this issue?
A) Set up an Amazon CloudWatch Events rule to forward all GuardDuty findings to the security account. Use an AWS Lambda function as a target to raise findings.
B) Set up an Amazon CloudWatch Events rule to forward all GuardDuty findings to the security account. Use an AWS Lambda function as a target to raise findings in AWS Security Hub.
C) Check that GuardDuty in the security account is able to assume a role in the compromised account using the guardduty;listfindings permission. Schedule an Amazon CloudWatch Events rule and an AWS Lambda function to periodically check for GuardDuty findings.
D) Use the aws guardduty get-members AWS CLI command in the security account to see if the account is listed. Send an invitation from GuardDuty in the security account to GuardDuty in the compromised account. Accept the invitation to forward all future GuardDuty findings.
Correct Answer:

Verified
Correct Answer:
Verified
Q208: A company had one of its Amazon
Q209: A Security Engineer must design a solution
Q210: The AWS Systems Manager Parameter Store is
Q211: A Development team has built an experimental
Q212: An application has been written that publishes
Q214: A company has complex connectivity rules governing
Q215: An Amazon S3 bucket is encrypted using
Q216: A company's security information events management (SIEM)
Q217: A distributed web application is installed across
Q218: The Security Engineer implemented a new vault