
Explanation:
Option A correctly uses Amazon EventBridge for event-driven automation and ASFF for standardizing security findings, which enhances the integration and interoperability of security tools.
Ultimate access to all questions.
You are required to configure integrations between native AWS services and third-party services to enhance your incident response capabilities. How would you use Amazon EventBridge and the AWS Security Finding Format (ASFF) to achieve this?
A
Use Amazon EventBridge to trigger AWS Lambda functions based on security events, and ASFF to standardize the format of security findings from third-party services.
B
Deploy Amazon GuardDuty to detect anomalies, Amazon Macie to identify sensitive data, and AWS Security Hub to manage the incident response.
C
Manually review AWS CloudTrail logs, use Amazon S3 for data storage, and AWS IAM for access control.
D
Block all network traffic using AWS Network Firewall, analyze logs with Amazon Elasticsearch, and use AWS Lambda for remediation scripts.
No comments yet.