AWS Certified Security – Specialty — Question 172

A company's on-premises data center forwards DNS logs to a third-party security incident events management (SIEM) solution that alerts on suspicious behavior.
The company wants to introduce a similar capability to its AWS accounts that includes automatic remediation. The company expects to double in size within the next few months.
Which solution meets the company's current and future logging requirements?

Answer options

Correct answer: A

Explanation

The correct answer, A, provides a comprehensive solution that integrates Amazon GuardDuty and AWS Security Hub for real-time threat detection and alerting, while also enabling automated remediation through AWS Lambda. Options B and C rely on the current on-premises SIEM, which does not meet the company's needs for automatic remediation and scalability. Option D does not address the automatic remediation requirement and focuses instead on access control.