SCS-C03 · Question #142
A company runs a web application on a fleet of Amazon EC2 instances that are in an Auto Scaling group. The EC2 instances are in the same VPC subnet as other workloads. A security engineer deploys an A
Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #142. The question stem and answer options stay visible for context.
Question
A company runs a web application on a fleet of Amazon EC2 instances that are in an Auto Scaling group. The EC2 instances are in the same VPC subnet as other workloads. A security engineer deploys an Amazon GuardDuty detector in the same AWS Region as the EC2 instances and integrates GuardDuty with AWS Security Hub. The security engineer needs to implement an automated solution to detect and appropriately respond to anomalous traffic patterns for the web application. The solution must comply with AWS best practices for initial response to security incidents and must minimize disruption to the web application. Which solution will meet these requirements?
Options
- ADisable the EC2 instance profile credentials by using AWS Lambda.
- BCreate an Amazon EventBridge rule that invokes an AWS Lambda function when GuardDuty
- CUpdate the subnet network ACL to block traffic from the detected source IP addresses.
- DSend GuardDuty findings to Amazon SNS for email notification.
Unlock SCS-C03 to see the answer
You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.