QuestionQ6

Detection

A company has recently configured Amazon GuardDuty and is receiving a large number of findings from IP addresses inside the company. A security engineer has confirmed that these IP addresses are trusted and permitted.

Which combination of steps should the security engineer perform to configure GuardDuty so it does not generate findings for these IP addresses?

Choose two
Explanation

Amazon GuardDuty trusted IP lists suppress findings involving the IP addresses they contain. For an IP address list, the entries are stored in a plaintext TXT file, with each IP address or CIDR range on a separate line. The file must be stored in Amazon S3, and the trusted IP list must reference that S3 location.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!