An online gaming company hosting its multiplayer game servers on Amazon EC2 wants to continuously monitor its AWS accounts for security threats like cryptocurrency mining, unauthorized API calls, and unusual data access patterns. The security team needs an intelligent service that automatically analyzes AWS CloudTrail logs, VPC Flow Logs, and DNS query logs to detect these anomalies. Which AWS service should the company use to meet this objective?
- AAmazon Inspector
- Amazon GuardDutyAnswer
- CAWS CloudTrail
- DAWS Shield Standard
Answer
Amazon GuardDuty
Amazon GuardDuty is the correct service because it provides continuous, intelligent threat detection. It analyzes data sources such as AWS CloudTrail event logs, VPC Flow Logs, and DNS query logs using machine learning and anomaly detection to identify threats like cryptocurrency mining, credential compromise, and communication with malicious servers.
Step-by-Step Solution
Key Concept
Continuous threat detection using Amazon GuardDuty
Estimated Time:1m 15s