ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 213 - SCS-C01 discussion

Report
Export

A company has Windows Amazon EC2 instances in a VPC that are joined to on-premises Active Directory servers for domain services. The security team has enabled Amazon GuardDuty on the AWS account to alert on issues with the instances.

During a weekly audit of network traffic, the Security Engineer notices that one of the EC2 instances is attempting to communicate with a known command-and-control server but failing. This alert does not show up in GuardDuty. Why did GuardDuty fail to alert to this behavior?

A.
GuardDuty did not have the appropriate alerts activated.
Answers
A.
GuardDuty did not have the appropriate alerts activated.
B.
GuardDuty does not see these DNS requests.
Answers
B.
GuardDuty does not see these DNS requests.
C.
GuardDuty only monitors active network traffic flow for command-and-control activity.
Answers
C.
GuardDuty only monitors active network traffic flow for command-and-control activity.
D.
GuardDuty does not report on command-and-control activity.
Answers
D.
GuardDuty does not report on command-and-control activity.
Suggested answer: B

Explanation:

https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_data-sources.html

https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_backdoor.html

asked 16/09/2024
Emmanuel Aminu
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first