Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 41 Topic 5 Discussion

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 41 Topic 5 Discussion

SCS-C03 Exam Topic 5 Question 41 Discussion:
Question #: 41
Topic #: 5

A security engineer must investigate an Amazon GuardDuty finding. The finding indicates potential cryptocurrency mining activity on an Amazon EC2 instance. The security engineer must validate the finding and assess the impact.

Which data sources should the security engineer analyze to meet these requirements?


A.

Check the instance’s CPU utilization metrics in Amazon CloudWatch. Examine the finding’s MITRE ATT & CK tactic classification. Review any associated IAM role permissions.


B.

Count the number of GuardDuty findings associated with the instance. Verify the instance’s launch time. Check AWS Security Hub CSPM for any related alerts.


C.

Review the instance’s process details that relate to the finding. Examine DNS queries to known mining domains. Analyze the instance’s outbound network connections by using VPC Flow Logs.


D.

Examine the instance’s AWS Systems Manager session history. Verify Amazon Route 53 DNS records. Review GuardDuty severity levels.


Get Premium SCS-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.