QuestionQ43

Incident Response

A company is developing an incident-response process to quarantine Amazon EC2 hosts that become infected with malware. The company uses an AWS Organizations organization to manage multiple AWS accounts. It configures AWS Security Hub in the organization to receive findings from multiple accounts running across multiple AWS Regions. A security engineer develops an AWS Lambda function that removes every rule from every security group for an EC2 instance suspected of malware infection.

Choose and order the correct steps to deploy and use the Lambda function as a custom action in Security Hub. Select each step once or not at all. (Select and order THREE.)

Community Discussion

No comments yet. Be the first to start the discussion!