nerdexam
Amazon

DOP-C02 · Question #152

A company manages a multi-tenant environment in its VPC and has configured Amazon GuardDuty for the corresponding AWS account. The company sends all GuardDuty findings to AWS Security Hub. Traffic fro

The correct answer is C. Configure a firewall in AWS Network Firewall. Create an AWS Lambda function that will create a. https://aws.amazon.com/blogs/security/automatically-block-suspicious-traffic-with-aws-network- firewall-and-amazon-guardduty/

Submitted by joshua94· Mar 6, 2026Incident & Event Response

Question

A company manages a multi-tenant environment in its VPC and has configured Amazon GuardDuty for the corresponding AWS account. The company sends all GuardDuty findings to AWS Security Hub. Traffic from suspicious sources is generating a large number of findings. A DevOps engineer needs to implement a solution to automatically deny traffic across the entire VPC when GuardDuty discovers a new suspicious source. Which solution will meet these requirements?

Options

  • ACreate a GuardDuty threat list. Configure GuardDuty to reference the list. Create an AWS
  • BConfigure an AWS WAF web ACL that includes a custom rule group. Create an AWS Lambda
  • CConfigure a firewall in AWS Network Firewall. Create an AWS Lambda function that will create a
  • DCreate an AWS Lambda function that will create a GuardDuty suppression rule. Configure the

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    21% (5)
  • C
    63% (15)
  • D
    13% (3)

Explanation

https://aws.amazon.com/blogs/security/automatically-block-suspicious-traffic-with-aws-network- firewall-and-amazon-guardduty/

Topics

#Amazon GuardDuty#AWS Network Firewall#AWS Lambda#Security Automation

Community Discussion

No community discussion yet for this question.

Full DOP-C02 Practice