AWS Certified Security – Specialty (SCS-C02) — Question 187

A company’s security engineer wants to receive an email alert whenever Amazon GuardDuty, AWS Identity and Access Management Access Analyzer, or Amazon Macie generate a high-severity security finding. The company uses AWS Control Tower to govern all of its accounts. The company also uses AWS Security Hub with all of the AWS service integrations turned on.

Which solution will meet these requirements with the LEAST operational overhead?

Answer options

Correct answer: B

Explanation

The correct answer is B because it directly utilizes Amazon EventBridge with a rule that matches Security Hub's high-severity findings, ensuring efficient integration with minimal management. The other options involve more complex setups, such as multiple Lambda functions or an EC2 application, which would increase operational overhead.