ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
An enterprise manages 25 AWS accounts through AWS Organizations. The security operations center needs to ingest a commercial IP and domain threat feed once and have it applied automatically across all accounts so Amazon GuardDuty can detect related activity, without operating extra infrastructure or running periodic scripts. Which solution best meets this requirement?
Designate a delegated GuardDuty administrator account, enable organization-wide GuardDuty, and create the external indicators as Threat Intelligence Sets in that account so they replicate to all member detectors.
Deploy an EC2 instance running an open-source threat platform in each account that retrieves the feed and pushes indicators to the local GuardDuty detector via API.
Enable AWS Security Hub cross-account aggregation and import the feed as custom findings in the master account, relying on Security Hub to forward indicators to GuardDuty for every member.
Store the feed in a central S3 bucket and create an AWS Config organization rule that invokes a Lambda function in each account to update GuardDuty threat lists hourly.
In a multi-account deployment, an AWS Organizations delegated GuardDuty administrator can centrally enable GuardDuty for all member accounts. When the administrator uploads an IPSet or ThreatIntelSet that contains external indicators, GuardDuty automatically distributes and applies the list to every associated member detector in all Regions. This provides immediate, continuous coverage without the need for additional EC2 hosts, Lambda jobs, Security Hub customization, or AWS Config rules. The other options either require per-account infrastructure, manual scripting, or rely on services that do not propagate threat intelligence sets to GuardDuty detectors.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Amazon GuardDuty?
Open an interactive chat with Bash
What is a Threat Intelligence Set in GuardDuty?
Open an interactive chat with Bash
How does AWS Organizations enhance GuardDuty management?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .