← AWS Security Specialty: evidence-based security
01 / 8 · 40 MIN

Detection and security evidence

Connect findings, sources, and actually observed coverage.

Concept and mechanism

Start detection strategy with events you need to observe and decisions depending on them. A finding is an analytical result, not necessarily a complete archive of original data. GuardDuty uses independent streams of foundational sources for detection; this does not provide a raw history managed by the team. If you need to query Flow Logs during a future investigation, configure your own collection, access, and retention. The DNS path also matters: the described GuardDuty source uses AWS resolvers, so a fleet with an external resolver can have a gap in that source. Do not present silence as proof of no activity.

Guided application

For CloudTrail, enabling integrity produces digests supporting checks for changes after delivery. Validation must be executed and its result retained; this feature does not itself prevent object writes. Keep preventive access and retention controls. Security Lake can centralize configured sources and normalize events into OCSF, with Parquet storage and bounded subscriber access. Define each consumer’s sources and Regions instead of treating normalization as global authorization. In a committee, distinguish integrated accounts from accounts still lacking collection. An acquisition is not covered merely by appearing in inventory. Record an owner, deadline, and alternative evidence for the gap while integration is prepared.

IN PRACTICE

GuardDuty detected activity, but nobody retained the Flow Logs requested for the last 90 days. Explain the gap and use only actually available evidence.

Common pitfalls

Finding as archive; digest as executed validation; central as complete; absence as health.

Related topics: Response, containment, and preservation · Networking and administrative access

Take this idea with you

Describe origin, period, integrity, and limits of the evidence used.

Create account

Reference: SCS-C03 domain 1 · SCS-C03