AWS Certified CloudOps Engineer - Associate

Security Hub and Automated Response

How to turn scattered findings from GuardDuty, Inspector, Macie, and Config into one prioritized queue and then act on it without a human in the loop: Security Hub CSPM aggregation and scoring, automation rules, EventBridge remediation, and where exposure findings and AWS Security Agent fit.

Intermediate 26 minutes 6 Learning Objectives
  1. Explain what Security Hub CSPM adds on top of the individual detectors and why AWS Config recording is a prerequisite
  2. Calculate how a standard's security score responds to passed, failed, unknown, and suppressed controls
  3. Configure cross-Region aggregation and choose between central and local configuration for an organization
  4. Distinguish automation rules from EventBridge rules and pick the right one for a stated requirement
  5. Build an automated remediation loop from finding to action to closed workflow status
  6. Place AWS Security Agent and Security Hub exposure findings against the runtime detectors covered so far