A retail company wants to continuously monitor its AWS accounts, Amazon EC2 instances, and container workloads for potential security threats, such as instances communicating with known malicious IP addresses or performing unauthorized API calls. The solution must use threat intelligence and machine learning to identify these anomalies. Which AWS service should the company use to meet these requirements?
- Amazon GuardDutyAnswer
- BAmazon Inspector
- CAWS CloudTrail
- DAWS Artifact
Answer
Amazon GuardDuty
Amazon GuardDuty is the correct choice because it is a dedicated threat detection service that continuously monitors for malicious activity and unauthorized behavior. It uses machine learning, anomaly detection, and integrated threat intelligence to identify threats such as cryptocurrency mining, credential compromise, or communications with known malicious command-and-control servers.
Step-by-Step Solution
Key Concept
Continuous threat detection using machine learning and threat intelligence in AWS.