0PricingLogin
AWS Security Academy · Lesson

Reading and Prioritizing GuardDuty Findings

Interpret severity scores to focus on the riskiest alerts first.

Why Prioritize

A busy account can generate many findings, and not all matter equally. To respond well you must prioritize, focusing first on the threats most likely to cause real harm. GuardDuty supports this with severity scores and rich finding detail that guide where to look first.

The Severity Score

Every GuardDuty finding carries a severity value from 0.1 to 8.9 and above, mapped to levels. Roughly, 1.0 to 3.9 is Low, 4.0 to 6.9 is Medium, and 7.0 to 8.9 is High. Higher numbers mean greater confidence and potential impact, so they jump the queue.

All lessons in this course

  1. What GuardDuty Detects and Why
  2. GuardDuty Data Sources and Finding Types
  3. Reading and Prioritizing GuardDuty Findings
  4. Enabling GuardDuty Across an Organization
← Back to AWS Security Academy