Soru

Zorluk: OrtaThreat Detection and Vulnerability Management

An online gaming company hosting its multiplayer game servers on Amazon EC2 wants to continuously monitor its AWS accounts for security threats like cryptocurrency mining, unauthorized API calls, and unusual data access patterns. The security team needs an intelligent service that automatically analyzes AWS CloudTrail logs, VPC Flow Logs, and DNS query logs to detect these anomalies. Which AWS service should the company use to meet this objective?

  1. A
    Amazon Inspector
  2. Amazon GuardDutyCevap
  3. C
    AWS CloudTrail
  4. D
    AWS Shield Standard

Cevap

Amazon GuardDuty
Amazon GuardDuty is the correct service because it provides continuous, intelligent threat detection. It analyzes data sources such as AWS CloudTrail event logs, VPC Flow Logs, and DNS query logs using machine learning and anomaly detection to identify threats like cryptocurrency mining, credential compromise, and communication with malicious servers.

Adım Adım Çözüm

1
Analyze the requirements in the scenario
The requirement is to choose an intelligent threat detection service that continuously analyzes AWS CloudTrail logs, VPC Flow Logs, and DNS query logs for active threats (like cryptocurrency mining and unauthorized API activity).
This helps identify which AWS security services are designed for runtime behavioral analysis and log-based threat detection.
2
Evaluate the options against their core functionality
Amazon GuardDuty is the specific AWS service that uses machine learning and threat intelligence to analyze AWS CloudTrail, VPC Flow Logs, and DNS logs. Amazon Inspector focuses on scanning resources for software vulnerabilities, AWS CloudTrail provides only logging without analysis, and AWS Shield Standard provides managed infrastructure-level DDoS protection.
This isolates the correct tool based on service definitions.

Anahtar Kavram

Continuous threat detection using Amazon GuardDuty
Tahmini Süre:1m 15s
Bu soruyu puanla