🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security team ingests Linux bastion-host logs from Amazon CloudWatch Logs into AWS Security Hub through an Amazon EventBridge rule. During a recent penetration test, thousands of authentication failure messages from a well-known Internet scanner generated so many findings that analysts struggled to spot truly suspicious activity. The team has already restricted the scanner's IP ranges at the VPC network ACL, but the repetitive log entries and resulting findings continue to arrive.

Which solution will best reduce alert noise while still ensuring that new malicious source IP addresses are detected and forwarded to Security Hub for investigation?

  • Configure a CloudWatch Logs subscription filter that streams events to an AWS Lambda function; have the function drop events from the scanner's IP ranges and forward only previously unseen sources to Security Hub.

  • Create GuardDuty suppression rules for the scanner's IP address ranges so findings that match those sources are automatically archived before analysts see them.

  • Disable SSH logging on the bastion host to prevent the generation of authentication failure messages that trigger the excessive findings.

  • Add a CloudWatch Logs metric filter that excludes every auth failure (FAILED_AUTH) record from the bastion-host log group so Security Hub no longer receives these events.

ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot