ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 234 - SCS-C02 discussion

Report
Export

A company has enabled Amazon GuardDuty in all AWS Regions as part of its security monitoring strategy. In one of its VPCs, the company hosts an Amazon EC2 instance that works as an FTP server. A high number of clients from multiple locations contact the FTP server. GuardDuty identifies this activity as a brute force attack because of the high number of connections that happen every hour.

The company has flagged the finding as a false positive, but GuardDuty continues to raise the issue. A security engineer must improve the signal-to-noise ratio without compromising the companys visibility of potential anomalous behavior.

Which solution will meet these requirements?

A.
Disable the FTP rule in GuardDuty in the Region where the FTP server is deployed.
Answers
A.
Disable the FTP rule in GuardDuty in the Region where the FTP server is deployed.
B.
Add the FTP server to a trusted IP list. Deploy the list to GuardDuty to stop receiving the notifications.
Answers
B.
Add the FTP server to a trusted IP list. Deploy the list to GuardDuty to stop receiving the notifications.
C.
Create a suppression rule in GuardDuty to filter findings by automatically archiving new findings that match the specified criteria.
Answers
C.
Create a suppression rule in GuardDuty to filter findings by automatically archiving new findings that match the specified criteria.
D.
Create an AWS Lambda function that has the appropriate permissions to de-lete the finding whenever a new occurrence is reported.
Answers
D.
Create an AWS Lambda function that has the appropriate permissions to de-lete the finding whenever a new occurrence is reported.
Suggested answer: C

Explanation:

'When you create an Amazon GuardDuty filter, you choose specific filter criteria, name the filter and can enable the auto-archiving of findings that the filter matches. This allows you to further tune GuardDuty to your unique environment, without degrading the ability to identify threats. With auto-archive set, all findings are still generated by GuardDuty, so you have a complete and immutable history of all suspicious activity.'

asked 16/09/2024
Sunil Reddy
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first