← AWS Certified DevOps Engineer - Professional
AWS · objective · 14% of the exam
Incident and Event Response — AWS Certified DevOps Engineer - Professional
The official AWS documentation our Incident and Event Response practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Amazon Web Services — Getting started with GuardDuty - Amazon GuardDuty
With EventBridge you can use GuardDuty findings to initiate automatic responses to your findings by connecting finding events to targets such as AWS Lambda functions,
-
Amazon Web Services — Integrating Systems Manager Automation runbooks in Incident Manager for incident remediation - Incident Manager
This role provides Incident Manager with the permissions it needs to access and start the workflow for the runbook. The Automation AssumeRole provides the permissions
-
Amazon Web Services — Creating CloudWatch alarms for CloudTrail events: examples - AWS CloudTrail
To create an alarm, you must first create a metric filter, and then configure an alarm based on the filter.
-
Amazon Web Services — Automatically address security threats with predefined response and remediation actions in AWS Security Hub - Automated Security Response on AWS
Each playbook contains the necessary custom actions, Identity and Access Management (IAM) roles, Amazon EventBridge rules , AWS Systems Manager automation documents, AWS Lambda functions,
-
Amazon Web Services — Automation rules in EventBridge - AWS Security Hub
To avoid sending duplicate findings, evaluate the rules you have defined for Security Hub CSPM to determine if they overlap with rules you are have
-
Amazon Web Services — Defining a rule in EventBridge - AWS Security Hub
"detail-type": [ "Security Hub Findings - Custom Action" ], "resources": [ " <custom action ARN> " ]
-
Amazon Web Services — What is Amazon Detective? - Amazon Detective
You can analyze the root cause for high severity GuardDuty findings using finding groups.