A hospitality booking portal hosts its application on Amazon EC2 instances and stores container images in Amazon Elastic Container Registry (ECR). The security team wants to continuously monitor their AWS accounts for malicious activity and unauthorized behavior, while also automatically scanning the EC2 instances and container images for software vulnerabilities.
Which two AWS services should the company use to meet these requirements? (Select two.)
- Amazon Inspector to scan the Amazon EC2 instances and Amazon ECR container images for software vulnerabilitiesCevap
- Amazon GuardDuty to perform intelligent threat detection and continuous monitoring for malicious activityCevap
- CAWS CloudTrail to monitor system performance metrics and resource logs on the EC2 instances
- DAmazon CloudWatch to record and audit all API operations and user activity within the AWS account
- EAWS Systems Manager to manage guest operating system updates, as these are managed automatically by AWS
Cevap
Amazon Inspector and Amazon GuardDuty
The service that scans Amazon EC2 instances and Amazon ECR container images for software vulnerabilities is Amazon Inspector. The service that provides intelligent threat detection and continuous monitoring for malicious activity is Amazon GuardDuty.
Adım Adım Çözüm
Anahtar Kavram
Differentiating AWS threat detection and vulnerability management services under the Shared Responsibility Model.