Bird
0
0

You want to monitor multiple AWS accounts for threats centrally using GuardDuty. What is the best approach?

hard📝 Application Q15 of 15
AWS - Advanced Security
You want to monitor multiple AWS accounts for threats centrally using GuardDuty. What is the best approach?
AUse GuardDuty's multi-account feature with a master account to manage findings centrally
BEnable GuardDuty separately in each account and region, then aggregate findings manually
CCreate IAM roles in each account to share logs with a central S3 bucket for GuardDuty analysis
DDisable GuardDuty in member accounts and rely on CloudTrail logs only
Step-by-Step Solution
Solution:
  1. Step 1: Understand GuardDuty multi-account setup

    GuardDuty supports a master account that can manage and view findings from member accounts centrally.
  2. Step 2: Evaluate other options

    Manual aggregation is inefficient, sharing logs via S3 is not how GuardDuty works, and disabling GuardDuty loses threat detection.
  3. Final Answer:

    Use GuardDuty's multi-account feature with a master account to manage findings centrally -> Option A
  4. Quick Check:

    GuardDuty multi-account = master account management [OK]
Quick Trick: Use GuardDuty master account for multi-account threat management [OK]
Common Mistakes:
  • Trying manual aggregation of findings
  • Using S3 buckets for GuardDuty log sharing
  • Disabling GuardDuty in member accounts

Want More Practice?

15+ quiz questions · All difficulty levels · Free

Free Signup - Practice All Questions
More AWS Quizzes