QuestionQ48

Detection

A company has hundreds of AWS accounts in an AWS Organizations organization. The company operates in a single AWS Region and has a dedicated security tooling AWS account in the organization. The security tooling account is configured as the organization's delegated administrator for Amazon GuardDuty and AWS Security Hub. The company has configured the environment to automatically enable GuardDuty and Security Hub for existing and new AWS accounts.

The company is conducting control tests on specific GuardDuty findings to ensure that the security team can detect and respond to security events. The security team launched an Amazon EC2 instance and tried to run DNS requests against a test domain, example.com, to produce a DNS finding. However, the GuardDuty finding was never created in the Security Hub delegated administrator account.

Why was the finding not created in the Security Hub delegated administrator account?

Explanation

Amazon GuardDuty can access and analyze Route 53 Resolver DNS query logs when Amazon EC2 instances use the default AWS DNS resolver. When a VPC DHCP option set specifies another resolver, such as OpenDNS, GuardDuty cannot access or process that DNS data. No GuardDuty DNS finding is therefore generated for Security Hub to receive.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!