A company's security team wants to receive near-real-time email notifications about AWS abuse reports related to DoS attacks. An Amazon SNS topic already exists and is subscribed to by the security team.
What should the security engineer do next?
AWS abuse notifications are delivered as AWS Health events. According to the AWS Certified Security -- Specialty Study Guide, Amazon EventBridge integrates natively with AWS Health and can be used to detect specific event types such as AWS_ABUSE_DOS_REPORT in near real time.
By creating an EventBridge rule that filters for the abuse report event type and publishes directly to Amazon SNS, the solution remains fully managed, low latency, and cost effective.
Polling APIs introduces delay and complexity. CloudTrail does not log abuse notifications. EventBridge with AWS Health is the recommended mechanism for reacting to AWS service events.
Referenced AWS Specialty Documents:
AWS Certified Security -- Specialty Official Study Guide
AWS Health and EventBridge Integration
AWS Abuse Notification Handling
Sol
4 days agoMirta
10 days agoAlyssa
15 days agoTamra
20 days agoKendra
25 days agoShelton
1 month agoLatrice
1 month agoDerick
2 months agoLeeann
2 months agoAhmed
2 months agoSheridan
2 months agoBrunilda
3 months agoCatalina
3 months agoKelvin
3 months ago