AWS Certified Security – SpecialtyDomain 1: Incident ResponseHard

A security engineer is setting up automated remediation for Amazon GuardDuty findings. Specifically, for a 'CredentialAccess:IAMUser/AnomalousBehavior' finding, the engineer wants to automatically revoke all active IAM access keys for the affected IAM user. This remediation must be idempotent and ensure that the keys are revoked even if the remediation is triggered multiple times for the same finding. Which AWS service should be used to achieve this automated and idempotent key revocation?

  1. AAWS Config with a custom remediation action.
  2. BAn AWS Lambda function triggered by Amazon EventBridge.
  3. CAWS Step Functions workflow.
  4. DAWS Systems Manager Automation documents.
Show answer & explanation

Correct answer: B. An AWS Lambda function triggered by Amazon EventBridge.

An AWS Lambda function triggered by Amazon EventBridge is the most suitable combination. EventBridge can filter for the specific GuardDuty finding. The Lambda function can then use the AWS SDK to identify and revoke active access keys for the affected IAM user. The key to idempotency here is that revoking an already revoked key has no further effect, and the Lambda function should be written to handle this gracefully.

Why the other options are wrong

  • A. AWS Config focuses on configuration compliance. While it can trigger remediation for non-compliant resources, GuardDuty findings are not directly Config rules, and the direct revocation of access keys is better handled by an event-driven Lambda function.
  • C. AWS Step Functions can orchestrate complex workflows, but for a single, direct remediation action like revoking keys, EventBridge triggering Lambda is simpler and more cost-effective. While Step Functions can achieve idempotency, it's overkill here.
  • D. Systems Manager Automation documents can perform actions, but EventBridge and Lambda are a more direct and serverless approach for event-driven API calls, and idempotency needs to be carefully built into the document.

Idempotent Automated Remediation

Idempotent automated remediation ensures that a security action (e.g., revoking access keys) can be safely executed multiple times without unintended side effects. This is often achieved using AWS Lambda triggered by EventBridge, with the Lambda function designed to handle repeated calls gracefully.

  • Idempotency means repeated execution yields same result.
  • EventBridge triggers Lambda for security findings.
  • Lambda functions use AWS SDK for remediation actions (e.g., IAM key rotation/deletion).

Memory trick: EventBridge and Lambda ensure your automated fixes are one-and-done, even if called twice.

More Domain 1: Incident Response questions