exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 219 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 219
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company's director of information security wants a daily email report from AWS that contains recommendations for each company account to meet AWS
Security best practices.
Which solution would meet these requirements?

  • A. In every AWS account, configure AWS Lambda to query the AWS Support API for AWS Trusted Advisor security checks. Send the results from Lambda to an Amazon SNS topic to send reports.
  • B. Configure Amazon GuardDuty in a master account and invite all other accounts to be managed by the master account. Use GuardDuty's integration with Amazon SNS to report on findings.
  • C. Use Amazon Athena and Amazon QuickSight to build reports off of AWS CloudTrail. Create a daily Amazon CloudWatch trigger to run the report daily and email it using Amazon SNS.
  • D. Use AWS Artifact's prebuilt reports and subscriptions. Subscribe the director of information security to the reports by adding the director as the security alternate contact for each account.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sanjaym
Highly Voted 3 years, 6 months ago
Answer: A Trusted Advisor for Best practices.
upvoted 28 times
...
cldy
Highly Voted 3 years, 6 months ago
A. - Trusted Advisor for best practices and it has AWS Support API.
upvoted 6 times
...
Raphaello
Most Recent 1 year, 1 month ago
Selected Answer: A
Look for Trusted Advisor for status checks and best practices. Answer A is correct.
upvoted 1 times
...
Green53
1 year, 10 months ago
Selected Answer: A
As per the docs: https://aws.amazon.com/premiumsupport/technology/trusted-advisor/ AWS Trusted Advisor provides recommendations that help you follow AWS best practices. Trusted Advisor evaluates your account by using checks. These checks identify ways to optimize your AWS infrastructure, improve security and performance, reduce costs, and monitor service quotas. You can then follow the recommendations to optimize your services and resources. A would provide 'recommendations' for 'best practices'. D might provided some recommendations, but I can't see a prebuild report being as actionable. I'd use AWS Artifact for accessing compliance documents and certificates.
upvoted 1 times
...
samCarson
1 year, 10 months ago
Selected Answer: A
A. In every AWS account, configure AWS Lambda to query the AWS Support API for AWS Trusted Advisor security checks. Send the results from Lambda to an Amazon SNS topic to send reports. This solution allows you to automate the process by using AWS Lambda to query the AWS Support API for Trusted Advisor security checks. The results can then be sent to an Amazon SNS topic, which can be subscribed to by the director of information security. This way, the director will receive a daily email report containing recommendations for each company account to meet AWS security best practices.
upvoted 2 times
...
pal40sg
1 year, 11 months ago
Selected Answer: D
AWS Artifact provides access to various prebuilt reports that contain important compliance and security information. These reports can be subscribed to and received via email. By subscribing the director of information security as the security alternate contact for each AWS account, they will receive the prebuilt reports on a regular basis, including recommendations for meeting AWS Security best practices.
upvoted 1 times
danielklein09
1 year, 10 months ago
regular does not mean "daily" - so it is option A
upvoted 1 times
...
pal40sg
1 year, 11 months ago
Option A suggests using AWS Lambda to query the AWS Support API for Trusted Advisor security checks and sending the results via Amazon SNS. While this approach can provide insights into security best practices, it does not offer a prebuilt report specifically tailored for the purpose.
upvoted 1 times
samCarson
1 year, 10 months ago
Option D (Use AWS Artifact's prebuilt reports and subscriptions) is more focused on accessing compliance reports rather than providing daily reports with recommendations for security best practices.
upvoted 1 times
...
...
...
Kezuko
1 year, 12 months ago
Selected Answer: A
Trusted Advisor for Best practices.
upvoted 1 times
...
ITGURU51
2 years ago
The answer is A due to the business use case. For example, Trusted Advisor can be used to send weekly or daily reports to your Chief Information Officer. Trusted Advisor is designed for internal IT compliance and best practices. However, AWS Artifact provides on demand access to AWS compliance documents which are better suited for auditors external to the business. PCI, SOX, NERC, NIST etc.
upvoted 1 times
...
Nikhil0222
2 years ago
A In this solution, AWS Lambda is used to query the AWS Support API for AWS Trusted Advisor security checks in every AWS account. The results are then sent to an Amazon SNS topic, which sends daily email reports to the director of information security. AWS Trusted Advisor provides best practice recommendations across multiple categories such as security, cost optimization, and fault tolerance. This makes it a suitable service for providing security recommendations.
upvoted 1 times
...
Maya77
2 years, 2 months ago
Selected Answer: D
Option D would be the best solution for the requirements. AWS Artifact provides a set of prebuilt reports that help customers understand and demonstrate their compliance with security and compliance regulations. These reports cover a range of services such as Amazon S3, Amazon EC2, AWS Identity and Access Management (IAM), AWS Key Management Service (KMS), and more. To meet the requirements, the director of information security can be added as the security alternate contact for each AWS account. This would allow the director to receive the prebuilt reports via email. The reports can be scheduled to be delivered daily, and they include recommendations for each service to meet AWS security best practices. This solution is easy to set up and provides the required daily reports without the need for additional configuration or custom code.
upvoted 2 times
nairj
2 years ago
Answer is A : AWS Artifact does not provide security best practices recommendations ,and there is no need to add the director as the backup of the security engineer. Option A uses AWS Trusted Advisor and uses lambda and SNS to automate the reporting part.
upvoted 2 times
...
...
ude
2 years, 8 months ago
Selected Answer: A
A it's correct
upvoted 2 times
...
kiev
3 years, 5 months ago
Trusted Advisor deals with security best practices and therefore A
upvoted 2 times
...
DahMac
3 years, 5 months ago
A. If you have a Basic or Developer Support plan, you can use the Trusted Advisor console to access all checks in the Service Limits category and six checks in the Security category. If you have a Business or Enterprise Support plan, you can use the Trusted Advisor console and the AWS Support API to access all Trusted Advisor checks. You also can use Amazon CloudWatch Events to monitor the status of Trusted Advisor checks. For more information, see Monitoring Trusted Advisor check results with Amazon CloudWatch Events. https://docs.aws.amazon.com/awssupport/latest/user/trusted-advisor.html
upvoted 3 times
...
AppSecurity
3 years, 6 months ago
Why not C?
upvoted 1 times
uninit
3 years, 3 months ago
It does not provide recommendations
upvoted 1 times
...
...
ChinkSantana
3 years, 6 months ago
D is totally wrong.. A is the answer here
upvoted 2 times
...
DayQuil
3 years, 6 months ago
Answer: A
upvoted 4 times
...
kk3322
3 years, 7 months ago
A I Think...
upvoted 3 times
viestner
3 years, 6 months ago
agree with you
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago