Detective Flashcards

1
Q

Detective

What is Detective?

A

Find root cause of security findings or suspicious activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Detective

What types of events is it most concerned with?

A

Time-based events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Detective

Sources of data?

A

CloudTrail, VPC Flow Logs, GuardDuty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Detective

How does it work?

A

ML to find outliers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Detective

How do you use Detective?

A

Interactively! You’re a detective following a trail of evidence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Detective

Example path of a human using Detective?

A

Start with a Finding, trace thru failed logins, other accesses by the target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Detective

What about cross-account?

A

Whichever account enabled Detective is the admin acct. Collect data across accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Detective

Example question it tries to answer?

A

Is this spike in traffic from this instances expected?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Detective

How do you do cross-account?

A

Organizations! Or, invite other accounts, then aggregates data across them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Detective

What are the account types in cross-accounts?

A

Administrator and Member (admin invites member accounts to join)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Detective

How does Detective work with AWS Organizations?

A

Org delegates to a Detective admin account, can auto-add other Org accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Detective

General work flow?

A

Let it log and analyze everything, it finds Findings (one-pagers).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Detective

Integration with GuardDuty?

A

Detective collects data and associates it to each GuardDuty Finding.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly