AWS GuardDuty Flashcards

1
Q

What is GuardDuty?

A

Threat detection, GD is looking at data sources in your account and identifying if there is a threat.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the structure of Guard Duty?

A

You have one account where Gard Duty is used and you can then invite other accounts, such as accounts in your orgnization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does Guard-duty identify threats?

A

Guard-duty monitors

  • Route 53
  • VPC Flow Logs
  • CloudTrail
  • AWS Accounts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Guard-duty finding?

A

This is an item thet is produced by GD when it detects a threat. We at a bunch of info like Severity, Region, Count, Threat Type, Affected Resource, Source info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do I receive events form GuardDuty?

A

CloudWatch Events, you can use CWE to trigger on other resources such an SNS, Lambda, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the sources GuardDuty is monitoring?

A
  • Route 53
  • VPC Flow Logs
  • CloudTrail
  • AWS Accounts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How cna you get threat intelligence form other accounts in you orgnization?

A

With GuardDuty you can invite other accounts in you orgnization to join and this becomes the master account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can an AWS account be a member of multiple GuardDutys account?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What have you to set up in GuardDuty to get GD started?

A

Service role permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

I have several IPs that are showing up in GuardDuty as a threat, what cna I do to stop this?

A

You can place the IP’s on a threat list to have them excluded from GD findings.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

I have knowing bad actor IP’s that I would like to know if these are seeing on our AWS networks, how cna I make this happen?

A

Add then to the threat list and these will be identified.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How many threat lists can you have per account?

A

You cna have 6 threat list per region per account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How many trusted lists can you have per account?

A

You cna have 1 per region per account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Are GuardDuty finding real-time?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Can you managed multiple accounts with guard duty?

A

Yes, it a bit different than other AWS services, you can ask other accounts to join.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Is the guard duty account the same as the org master account?

A

No, completely different, GD can be any aw2s acc you chose it to be, you then use GD to ask other accounts join.

17
Q

Can an AWS account be a member of more than one GD?

A

No, only be a member of one GD.

18
Q

I am getting my findings from guard duty, when I investigate I find they are false and the device is an external device on the internet belong to me, how can I fix this, should I contact aws?

A

No, do not contact AWS. Just add IP to the whitelist.

19
Q

I know there are bad actors coming from an IP, is it possible to add this to GuardDuty?

A

Yes, add it to the threat list.

20
Q

Is there one trusted list per GD or one per account?

A

One per account.

21
Q

Are the finding in GD realtime?

A

No, but they arrive prompt.