ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 175 - SCS-C01 discussion

Report
Export

An organization wants to be alerted when an unauthorized Amazon EC2 instance in its VPC performs a network port scan against other instances in the VPC. When the Security team performs its own internal tests in a separate account by using pre-approved third-party scanners from the AWS Marketplace, the Security team also then receives multiple Amazon GuardDuty events from Amazon CloudWatch alerting on its test activities. How can the Security team suppress alerts about authorized security tests while still receiving alerts about the unauthorized activity?

A.
Use a filter in AWS CloudTrail to exclude the IP addresses of the Security team’s EC2 instances.
Answers
A.
Use a filter in AWS CloudTrail to exclude the IP addresses of the Security team’s EC2 instances.
B.
Add the Elastic IP addresses of the Security team’s EC2 instances to a trusted IP list in Amazon GuardDuty.
Answers
B.
Add the Elastic IP addresses of the Security team’s EC2 instances to a trusted IP list in Amazon GuardDuty.
C.
Install the Amazon Inspector agent on the EC2 instances that the Security team uses.
Answers
C.
Install the Amazon Inspector agent on the EC2 instances that the Security team uses.
D.
Grant the Security team’s EC2 instances a role with permissions to call Amazon GuardDuty API operations.
Answers
D.
Grant the Security team’s EC2 instances a role with permissions to call Amazon GuardDuty API operations.
Suggested answer: B

Explanation:

Trusted IP lists consist of IP addresses that you have whitelisted for secure communication with your AWS infrastructure and applications. GuardDuty does not generate findings for IP addresses on trusted IP lists. At any given time, you can have only one uploaded trusted IP list per AWS account per region. Threat lists consist of known malicious IP addresses. GuardDuty generates findings based on threat lists. At any given time, you can have up to six uploaded threat lists per AWS account per region. https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_upload_lists.html

asked 16/09/2024
Mohammed Hamid
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first