An organization wants to be alerted when an unauthorized Amazon EC2 instance in its VPC performs a network port scan against other instances in the VPC.
When the Security team performs its own internal tests in a separate account by using pre-approved third-party scanners from the AWS Marketplace, the Security team also then receives multiple Amazon GuardDuty events from Amazon CloudWatch alerting on its test activities.
How can the Security team suppress alerts about authorized security tests while still receiving alerts about the unauthorized activity?
polo
Highly Voted 3 years, 8 months agoAnNguyen
Highly Voted 3 years, 7 months agoNuha_23
Most Recent 1 year, 9 months agoaddy_prepare
1 year, 9 months agomatrpro
2 years agoawsexamer2023
2 years, 2 months agoSuhasj02
2 years, 3 months agoAbeis
2 years, 4 months agoDara2315
2 years, 4 months ago[Removed]
2 years, 6 months agolotfi50
2 years, 11 months agoNSF2
3 years, 6 months agohk436
3 years, 6 months agoEA_Practice
3 years, 6 months agoEA_Practice
3 years, 6 months agoscuzzy2010
3 years, 6 months agosanjaym
3 years, 6 months agoTolaji
3 years, 6 months agodurmusc
3 years, 6 months ago