Answers
Here are the answers to this chapter’s questions:
- Detective acts as an analytical extension to GuardDuty by ingesting and correlating data from various AWS services. It employs ML algorithms for pattern identification and offers graphical visualization for a better understanding of security events. It also groups related GuardDuty findings and maps them to the MITRE ATT&CK framework.
- Guardrails in Control Tower are pre-packaged governance rules that enforce compliance and security policies across your AWS accounts. They can be either preventive or detective. Preventive guardrails restrict actions that could violate policies, while detective guardrails monitor for non-compliance and report it. This dual approach ensures both proactive and reactive governance. As an example, a preventive guardrail could restrict the creation of S3 buckets that are publicly accessible, while a detective guardrail could flag an EC2 instance launched without required tags...