nerdexam
Amazon

SCS-C02 · Question #37

A company has deployed Amazon GuardDuty and now wants to implement automation for potential threats. The company has decided to start with RDP brute force attacks that come from Amazon EC2 instances i

The correct answer is C. Enable AWS Security Hub to ingest GuardDuty findings and send the event to Amazon. https://aws.amazon.com/blogs/security/automatically-block-suspicious-traffic-with-aws-network- firewall-and-amazon-guardduty/

Submitted by jordan8· Mar 6, 2026Threat Detection and Incident Response

Question

A company has deployed Amazon GuardDuty and now wants to implement automation for potential threats. The company has decided to start with RDP brute force attacks that come from Amazon EC2 instances in the company's AWS environment. A security engineer needs to implement a solution that blocks the detected communication from a suspicious instance until investigation and potential remediation can occur. Which solution will meet these requirements?

Options

  • AConfigure GuardDuty to send the event to an Amazon Kinesis data stream. Process the event
  • BConfigure GuardDuty to send the event to Amazon EventBridge. Deploy an AWS WAF web ACL.
  • CEnable AWS Security Hub to ingest GuardDuty findings and send the event to Amazon
  • DEnable AWS Security Hub to ingest GuardDuty findings. Configure an Amazon Kinesis data

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    15% (5)
  • C
    76% (26)
  • D
    6% (2)

Explanation

https://aws.amazon.com/blogs/security/automatically-block-suspicious-traffic-with-aws-network- firewall-and-amazon-guardduty/

Topics

#GuardDuty findings#EventBridge automation#Security Hub#incident remediation

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice