A security operations center (SOC) needs to create a custom dashboard in Amazon CloudWatch to monitor suspicious activities detected by Amazon GuardDuty across multiple AWS accounts. The dashboard should display key GuardDuty findings, such as the total number of findings, findings by severity, and findings by type. Which steps are required to achieve this, assuming GuardDuty is already enabled in all accounts?
- AConfigure GuardDuty to send findings to Amazon EventBridge, then create CloudWatch Metrics from EventBridge events, and add these metrics to a custom dashboard.
- BConfigure GuardDuty to publish findings directly to CloudWatch Dashboards.
- CCreate CloudWatch alarms for each GuardDuty finding type and add these alarms to a custom dashboard.
- DEnable CloudTrail logging for GuardDuty API calls, send logs to CloudWatch Logs, and create metric filters from the logs for the dashboard.
Show answer & explanationAnswer & explanation
Correct answer: A. Configure GuardDuty to send findings to Amazon EventBridge, then create CloudWatch Metrics from EventBridge events, and add these metrics to a custom dashboard.
Amazon GuardDuty publishes its findings to Amazon EventBridge. From EventBridge, you can create rules to match specific GuardDuty finding patterns. These rules can then trigger actions, including pushing custom metrics to CloudWatch. Once the metrics are in CloudWatch, you can easily add them to a custom dashboard to visualize the total number of findings, findings by severity, or findings by type.
Why the other options are wrong
- B. GuardDuty does not publish findings directly to CloudWatch Dashboards. It publishes to EventBridge.
- C. While you can create CloudWatch Alarms on metrics, the first step is to get the GuardDuty findings into CloudWatch Metrics. Alarms are for notification, not for displaying aggregated data on a dashboard.
- D. CloudTrail logs GuardAPI calls (management events related to GuardDuty configuration), not the actual security findings generated by GuardDuty itself. This approach would not give you the findings data needed for the dashboard.
GuardDuty Findings to CloudWatch Metrics
The process of forwarding Amazon GuardDuty security findings, which are published to Amazon EventBridge, to Amazon CloudWatch as custom metrics for monitoring and visualization on dashboards.
- GuardDuty findings are emitted as events to EventBridge.
- EventBridge rules can filter and transform these events.
- Custom metrics can be published to CloudWatch based on EventBridge events.
- CloudWatch Dashboards visualize these metrics for security monitoring.
Memory trick: EventBridge routes GuardDuty findings to CloudWatch metrics, dashboard shows the story.