passdrill
AWS SAA-C03 · IAM & Security · Card 018/024 medium

A security team already runs Amazon GuardDuty, Amazon Macie, and Amazon Inspector across their accounts and now wants one dashboard that ingests and normalizes findings from all three, and separately checks their environment against a security industry standard such as the CIS AWS Foundations Benchmark, prioritizing everything in a single place. Which service should they add?

  1. AWS Config, configured with enough custom rules to independently reproduce each of these checks
  2. AWS Systems Manager, to patch instances and inspect general operational configuration
  3. Amazon Detective, to visualize the likely root cause of one already-known security finding
  4. AWS Security Hub, which ingests and normalizes findings from services such as GuardDuty, Macie, and Inspector into a standard format, and separately runs its own checks against security standards such as the CIS AWS Foundations Benchmark
Next card → Shuffle