nerdexam
Amazon

DOP-C02 · Question #176

A company hired a penetration tester to simulate an internal security breach. The tester performed port scans on the company's Amazon EC2 instances. The company's security measures did not detect…

The correct answer is A. Ensure that Amazon GuardDuty is enabled. Create an Amazon CloudWatch alarm for detected. https://aws.amazon.com/blogs/security/amazon-inspector-assess-network-exposure-ec2- instances-aws-network-reachability-assessments/

Submitted by kwame.gh· Mar 6, 2026Incident and Event Response

Question

A company hired a penetration tester to simulate an internal security breach. The tester performed port scans on the company's Amazon EC2 instances. The company's security measures did not detect the port scans. The company needs a solution that automatically provides notification when port scans are performed on EC2 instances. The company creates and subscribes to an Amazon Simple Notification Service (Amazon SNS) topic. What should the company do next to meet the requirement?

Options

  • AEnsure that Amazon GuardDuty is enabled. Create an Amazon CloudWatch alarm for detected
  • BEnsure that Amazon Inspector is enabled. Create an Amazon EventBridge event for detected
  • CEnsure that Amazon Inspector is enabled. Create an Amazon EventBridge event for detected
  • DEnsure that AWS CloudTrail is enabled. Create an AWS Lambda function to analyze the

How the community answered

(65 responses)
  • A
    83% (54)
  • B
    9% (6)
  • C
    5% (3)
  • D
    3% (2)

Explanation

https://aws.amazon.com/blogs/security/amazon-inspector-assess-network-exposure-ec2- instances-aws-network-reachability-assessments/

Topics

#Amazon GuardDuty#Threat detection#Port scanning#Amazon SNS

Community Discussion

No community discussion yet for this question.

Full DOP-C02 Practice