DOP-C02 · Question #117
A company runs applications in AWS accounts that are in an organization in AWS Organizations. The applications use Amazon EC2 instances and Amazon S3. The company wants to detect potentially…
The correct answer is A. In the organization's management account, configure an AWS account as the Amazon GuardDuty. If the account that you want to specify as the GuardDuty administrator account is part of an organization in AWS Organizations, then you can specify that account as the organization's delegated administrator for GuardDuty. The account that is registered as the delegated…
Question
A company runs applications in AWS accounts that are in an organization in AWS Organizations. The applications use Amazon EC2 instances and Amazon S3. The company wants to detect potentially compromised EC2 instances, suspicious network activity, and unusual API activity in its existing AWS accounts and in any AWS accounts that the company creates in the future. When the company detects one of these events, the company wants to use an existing Amazon Simple Notification Service (Amazon SNS) topic to send a notification to its operational support team for investigation and remediation. Which solution will meet these requirements in accordance with AWS best practices?
Options
- AIn the organization's management account, configure an AWS account as the Amazon GuardDuty
- BIn the organization's management account, configure Amazon GuardDuty to add newly created AWS
- CIn the organization's management account, create an AWS CloudTrail organization trail. Activate the
- DIn the organization's management account, configure an AWS account as the AWS CloudTrail
How the community answered
(26 responses)- A85% (22)
- B4% (1)
- C8% (2)
- D4% (1)
Explanation
If the account that you want to specify as the GuardDuty administrator account is part of an organization in AWS Organizations, then you can specify that account as the organization's delegated administrator for GuardDuty. The account that is registered as the delegated administrator automatically becomes the GuardDuty administrator account. You can use this administrator account to enable and manage GuardDuty for any account in the organization when you add that account as a member account. https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_accounts.html
Topics
Community Discussion
No community discussion yet for this question.