GuardDuty Flashcards

1
Q

What is GuardDuty

A

a service that analyzes VPC flow log, DNS log, S3 data events and CloudTrail management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who can enable GuardDuty

A

admin user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How long data is stored in GuardDuty

A

90 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the recommended approach to keep track of ‘findings’ by GuardDuty

A

store in S3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How can someone be notified if a security threat is being detected by GuardDuty

A
  1. Create SNS topic
  2. Create EventBridge rule to capture findings from GuardDuty
  3. Ensure that EventBridge is able to push the finding to the SNS topic
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is account

A

Account that contains resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is member accounts

A

It is possible to invite other aws account to join the administrative account - in which case the accounts are called as member account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Detector

A

a logical component per region that represents a GuardDuty service in that region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Data Source

A

sources of data - that GuardDuty analyzes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is findings

A

findings discovered by GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is suppression rule

A

an expression to suppress a finding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is trusted IP list

A

a list of IP addresses for which GuardDuty does not generate findings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Threat List

A

a malicious list of IP addresses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly