GuardDuty Flashcards
What is GuardDuty
a service that analyzes VPC flow log, DNS log, S3 data events and CloudTrail management
Who can enable GuardDuty
admin user
How long data is stored in GuardDuty
90 days
What is the recommended approach to keep track of ‘findings’ by GuardDuty
store in S3
How can someone be notified if a security threat is being detected by GuardDuty
- Create SNS topic
- Create EventBridge rule to capture findings from GuardDuty
- Ensure that EventBridge is able to push the finding to the SNS topic
What is account
Account that contains resources
What is member accounts
It is possible to invite other aws account to join the administrative account - in which case the accounts are called as member account
What is a Detector
a logical component per region that represents a GuardDuty service in that region
What is Data Source
sources of data - that GuardDuty analyzes
What is findings
findings discovered by GuardDuty
What is suppression rule
an expression to suppress a finding
What is trusted IP list
a list of IP addresses for which GuardDuty does not generate findings
What is Threat List
a malicious list of IP addresses