A SaaS provider hosts its web application on Amazon EC2 instances and stores container images in Amazon Elastic Container Registry (Amazon ECR). The security team needs to implement automated tools to accomplish two tasks:
1. Continually scan the EC2 instances and container images for software vulnerabilities and unintended network exposure.
2. Monitor AWS account activity and network traffic to detect anomalous behavior, potential unauthorized access, and malicious threats.
Which two AWS services should the company use to meet these requirements? (Select two.)
- Amazon InspectorCevap
- Amazon GuardDutyCevap
- CAWS Artifact
- DAmazon CloudWatch
- EAWS Key Management Service (AWS KMS)
Cevap
Amazon Inspector and Amazon GuardDuty should be used to scan for software vulnerabilities and detect malicious threats, respectively.
Amazon Inspector automatically and continuously scans EC2 instances and ECR container images for software vulnerabilities and unintended network exposure. Amazon GuardDuty provides continuous threat detection by monitoring AWS account activity and network traffic to identify potential malicious activity.
Adım Adım Çözüm
Anahtar Kavram
AWS threat detection and vulnerability management services
Tahmini Süre:1m 30s