Zum Hauptinhalt springen

Meilenstein 1: Automated-Incident-Response-Capstone

Entwirf einen Multi-Account-Workflow, der:

  • AWS Health-, CloudTrail-, Application- und Compliance-Events empfängt,
  • Severity und Ownership klassifiziert,
  • Resource- und Deployment-Context enriched,
  • Operational Work Item oder Incident Record erstellt,
  • Responder notifyt und eskaliert,
  • eine sichere Systems-Manager- oder Step-Functions-Remediation ausführt,
  • Failed Events speichert,
  • Recovery verifiziert,
  • vollständige Timeline erfasst,
  • Post-Incident Actions erstellt.

Destruktive oder High-Risk-Actions benötigen Manual Approval.