A retail company wants to continuously monitor its AWS accounts and workloads for malicious activity, including potential cryptocurrency mining and unauthorized API usage. The solution must require minimal operational overhead and provide automated threat intelligence. Which AWS service should a solutions architect recommend to meet these requirements?
- AAWS Shield
- BNetwork Access Control Lists (Network ACLs)
- Amazon GuardDutyAnswer
- DAWS WAF
Answer
Amazon GuardDuty is the correct AWS service to recommend because it provides intelligent threat detection and continuous monitoring for malicious activities like cryptocurrency mining and unauthorized API usage.
Amazon GuardDuty continuously monitors AWS accounts and workloads using data sources like VPC Flow Logs, CloudTrail management events, and DNS logs. It uses machine learning, anomaly detection, and threat intelligence to identify malicious activities like cryptocurrency mining or unauthorized access, satisfying the requirements with minimal operational overhead.
Step-by-Step Solution
Key Concept
Continuous security monitoring and threat detection using Amazon GuardDuty