A security team wants continuous, intelligent threat detection across accounts by analyzing CloudTrail, VPC Flow Logs, and DNS logs, with no agents to deploy. Which service should they enable?
AWS Certified Security โ Specialty
AWS_SCS_C02Ready to test yourself?
A timed, blueprint-proportional exam drawn fresh from this bank โ with a per-domain score report.
๐ Free preview: showing 10 of 100 questions. Unlock the full bank โ every question, explanation, and reference.
Unlock all 100 questions โ10 questions across 6 topics. Choose an answer for each question, then check it to see the correct answer and explanation.
Filter by topic
4 questions in Threat Detection and Incident Response
Threat Detection and Incident Response
4 questions in topicDetect, analyze, and respond to security threats and incidents on AWS.
After GuardDuty raises a finding about suspicious activity from an IAM role, an analyst must investigate the root cause by correlating activity across accounts and time using a visual graph. Which service is designed for this security investigation?
An EC2 instance is suspected of being compromised. Following incident-response best practices, what should the security engineer do to contain it while preserving evidence?
A team wants specific GuardDuty findings to automatically trigger a remediation workflow (for example, isolating an instance) with no manual steps. Which approach achieves this?