SOA-C02 Question 223
Single answerYour organization uses AWS Security Hub to monitor compliance and Amazon GuardDuty for threat detection. During a routine review, you notice several findings flagged as 'High' severity in AWS Security Hub. What is the best course of action to handle these findings?
- A
Investigate the high-severity findings in AWS Security Hub and use the remediation actions recommended in the findings.
- B
Delete all high-severity findings in AWS Security Hub, assuming they have been addressed automatically.
- C
Disable the 'High' severity findings in AWS Security Hub to avoid receiving future notifications.
- D
Export the findings from AWS Security Hub and Amazon GuardDuty into an external tool for investigation without further action in AWS.
Show answer and explanation
Correct answer: A
Explanation
AWS Security Hub findings flagged as 'High' severity indicate critical issues that require immediate attention. The best practice is to investigate these findings and follow the recommended remediation steps provided by AWS. This ensures that security vulnerabilities are addressed promptly and effectively. Ignoring, deleting, or disabling findings can leave your environment exposed to potential threats.
- A. Correct.
This is the correct answer. AWS Security Hub findings provide specific remediation steps to address issues. Reviewing and acting on these recommended actions ensures that security risks are mitigated.
- B. Incorrect.
Deleting findings without investigation could leave unresolved security issues in your environment. Findings should be analyzed and remediated instead of being removed arbitrarily.
- C. Incorrect.
Disabling findings without addressing them could result in missing critical security risks. High-severity findings should always be investigated and resolved appropriately.
- D. Incorrect.
While exporting findings for further analysis can be helpful, it is not the best initial course of action. Findings should first be investigated and acted upon within AWS as recommended by the associated services.