A telemedicine platform hosts its patient portal application on Amazon EC2 instances. The platform's security team needs to implement a solution that continuously monitors the AWS account for malicious activity and unauthorized access, while also automatically scanning the EC2 instances for known software vulnerabilities and unintended network exposure. Which two AWS services should the security team use to meet these requirements? (Select two.)
- Amazon GuardDutyCevap
- Amazon InspectorCevap
- CAWS CloudTrail
- DAmazon CloudWatch
- EAWS Shield
Cevap
Amazon GuardDuty and Amazon Inspector are the correct services. Amazon GuardDuty provides continuous threat detection across the AWS environment, while Amazon Inspector scans the EC2 instances for software vulnerabilities and network exposure.
Amazon GuardDuty continuously monitors AWS accounts and workloads for malicious activity such as credential compromise or malware, while Amazon Inspector automatically scans EC2 instances for software vulnerabilities and unintended network exposure. Together, they satisfy the requirement for both threat detection and vulnerability scanning.
Adım Adım Çözüm
Anahtar Kavram
AWS threat detection and vulnerability management services