
Answer-first summary for fast verification
Answer: Leverage both AWS CloudTrail for event history and Amazon GuardDuty for threat detection to investigate the incident and implement preventive measures such as bucket policies and access controls.
Option B is correct because it uses both AWS CloudTrail and Amazon GuardDuty for a detailed investigation and implements preventive measures, which are crucial for preventing future data leaks.
Author: LeetQuiz Editorial Team
Ultimate access to all questions.
No comments yet.
Imagine you are part of an incident response team dealing with a potential data leak from an AWS S3 bucket. How would you use AWS CloudTrail and Amazon GuardDuty to investigate the incident and what steps would you take to prevent future leaks? Describe the process from detection to prevention.
A
Use only AWS CloudTrail for basic logging without detailed investigation.
B
Leverage both AWS CloudTrail for event history and Amazon GuardDuty for threat detection to investigate the incident and implement preventive measures such as bucket policies and access controls.
C
Ignore Amazon GuardDuty and rely solely on AWS CloudTrail.
D
Assume no leak occurred without investigation.