AWS Certified DevOps Engineer – ProfessionalIncident and Event ResponseHard

A financial services company uses AWS for its critical applications. Regulatory compliance requires that all security incidents be handled according to a strict, auditable process. The security team wants to automate the initial containment and data collection for incidents involving Amazon EC2 instances that are flagged for suspicious network activity by Amazon GuardDuty. Which combination of AWS services provides the MOST effective and auditable automated response?

  1. AConfigure Amazon EventBridge to detect GuardDuty findings, trigger an AWS Systems Manager Automation document to isolate the EC2 instance and collect forensic data, and record the action in AWS Security Hub.
  2. BSet up Amazon CloudWatch Alarms on GuardDuty metrics, trigger an AWS Lambda function to stop the EC2 instance, and store instance snapshots in an S3 bucket.
  3. CConfigure Amazon EventBridge to detect GuardDuty findings, trigger an AWS Lambda function to detach the EC2 instance's network interface, and log the action to Amazon CloudWatch Logs.
  4. DUse AWS Config rules to monitor for GuardDuty findings, trigger an AWS Step Functions workflow to terminate the EC2 instance, and send notifications via Amazon SNS.
Show answer & explanation

Correct answer: A. Configure Amazon EventBridge to detect GuardDuty findings, trigger an AWS Systems Manager Automation document to isolate the EC2 instance and collect forensic data, and record the action in AWS Security Hub.

This solution leverages EventBridge for event detection, Systems Manager Automation for sophisticated, auditable containment and data collection, and Security Hub for centralized security posture management, which is crucial for regulatory compliance in financial services.

Why the other options are wrong

  • B. CloudWatch Alarms are not the most direct way to react to GuardDuty findings (EventBridge is better), and simply stopping an instance might not fully contain an advanced threat or collect all necessary forensic data. Storing snapshots in S3 is good for data but lacks the full orchestration and auditability of other services.
  • C. Detaching a network interface is a valid containment step, but it doesn't provide forensic data collection or a centralized audit trail for the entire response process, which is essential for compliance.
  • D. Terminating an instance immediately might destroy crucial forensic evidence. While Step Functions can orchestrate, AWS Config rules are not the primary mechanism for reacting to real-time GuardDuty findings, and SNS is just for notification, not full incident management.

Automated Incident Response with SSM Automation

Using AWS Systems Manager Automation documents, orchestrated by services like EventBridge, to automatically respond to security incidents by containing threats, collecting forensic data, and recording actions.

  • EventBridge detects security findings (e.g., GuardDuty).
  • SSM Automation documents execute predefined runbooks for response actions.
  • Actions can include isolation, data collection, and notification.
  • Provides an auditable trail of actions for compliance.

Memory trick: GuardDuty alerts, EventBridge triggers, SSM automates, Security Hub audits.

More Incident and Event Response questions