AWS Certified CloudOps Engineer - Associate
Security Hub and Automated Response
How to turn scattered findings from GuardDuty, Inspector, Macie, and Config into one prioritized queue and then act on it without a human in the loop: Security Hub CSPM aggregation and scoring, automation rules, EventBridge remediation, and where exposure findings and AWS Security Agent fit.
Intermediate 26 minutes 6 Learning Objectives
- Explain what Security Hub CSPM adds on top of the individual detectors and why AWS Config recording is a prerequisite
- Calculate how a standard's security score responds to passed, failed, unknown, and suppressed controls
- Configure cross-Region aggregation and choose between central and local configuration for an organization
- Distinguish automation rules from EventBridge rules and pick the right one for a stated requirement
- Build an automated remediation loop from finding to action to closed workflow status
- Place AWS Security Agent and Security Hub exposure findings against the runtime detectors covered so far
