A retail company wants to implement a solution to continuously monitor its AWS accounts and workloads for threat patterns, such as Amazon EC2 instances communicating with known malicious IP addresses or unexpected IAM activity. Which AWS service should the company use to meet this requirement?
- Amazon GuardDutyAnswer
- BAWS Shield
- CAWS WAF
- DAmazon VPC Security Groups
Answer
Amazon GuardDuty
Amazon GuardDuty is the correct choice because it is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It uses threat intelligence feeds and machine learning to identify signatures such as cryptocurrency mining, communication with known command-and-control servers, and abnormal API patterns.
Step-by-Step Solution
Key Concept
Continuous threat detection and security monitoring across workloads and account activity using Amazon GuardDuty.
Estimated Time:45s