AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company uses AWS Organizations to manage a multi-account environment. A dedicated Security account has been designated as the delegated administrator for Amazon GuardDuty, consolidating findings from all member accounts. The security team wants to implement an automated, centralized response to a specific high-severity GuardDuty finding, CryptoCurrency:EC2/BitcoinTool.B, which indicates an EC2 instance may be compromised for cryptocurrency mining. The required remediation action is to immediately isolate the affected EC2 instance by replacing its existing security groups with a single, pre-defined 'Quarantine' security group.

Which solution meets these requirements in the most secure and operationally efficient manner?

  • In the Security account, create an Amazon EventBridge rule that filters for the specific GuardDuty finding. Configure the rule to trigger an AWS Lambda function. The Lambda function will assume a cross-account IAM role in the member account to modify the EC2 instance's security groups.

  • Configure GuardDuty to export all findings to a centralized Amazon S3 bucket in the Security account. Use S3 Event Notifications to trigger an AWS Lambda function that parses the finding, assumes a role into the member account, and modifies the EC2 instance's security groups.

  • In the Security account, create an AWS Lambda function containing IAM user credentials for each member account. Create an Amazon EventBridge rule that triggers this function for the specific GuardDuty finding, using the stored credentials to call the EC2 API in the appropriate member account.

  • In each member account, create an Amazon EventBridge rule that filters for the specific GuardDuty finding. Configure the rule to trigger a local AWS Lambda function within the same account that modifies the EC2 instance's security groups.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot