Soru

Zorluk: ZorThreat Detection and Vulnerability Management

A financial company hosts a transaction processing application on Amazon EC2 instances and stores historical data archives in Amazon S3. The security team must implement a security strategy that achieves two goals: first, automatically identifying software package vulnerabilities and unintended network accessibility on the EC2 instances; second, continuously monitoring the AWS accounts and network traffic for active malicious activity, such as brute-force attacks or communication with known malicious command-and-control servers. Which of the following AWS services should be implemented to address these specific security requirements? (Select two.)

  1. Amazon Inspector to scan the EC2 instances for software vulnerabilities and unintended network exposure.Cevap
  2. Amazon GuardDuty to continuously monitor account activity and network logs for signatures of malicious behavior.Cevap
  3. C
    AWS CloudTrail to perform automated vulnerability scanning on the application's hosting infrastructure.
  4. D
    Amazon CloudWatch to automatically detect account-level anomalies and alert on communication with malicious IP addresses.
  5. E
    AWS WAF to scan Amazon S3 buckets and identify OS-level patch deficiencies on the EC2 hosts.

Cevap

The correct services are Amazon Inspector and Amazon GuardDuty.
The correct services are Amazon Inspector and Amazon GuardDuty. Amazon Inspector satisfies the first requirement by continuously scanning EC2 instances for software vulnerability packages and mapping network reachability. Amazon GuardDuty satisfies the second requirement by analyzing VPC Flow Logs, DNS logs, and CloudTrail events to identify active threats like brute-force attacks or communication with malicious IP addresses.

Adım Adım Çözüm

1
Analyze the requirement for host-level software vulnerability and network reachability scanning on EC2 instances.
Identify Amazon Inspector as the service that automates software package vulnerability scanning and checks for unintended external network paths.
Vulnerability scanning of EC2 operating system packages and network path analysis is the core function of Amazon Inspector.
2
Analyze the requirement for active, intelligent threat detection and anomaly monitoring at the AWS account level.
Identify Amazon GuardDuty as the service that monitors log metadata (VPC Flow Logs, DNS, CloudTrail) to flag malicious communications and brute-force attempts.
Amazon GuardDuty uses machine learning and threat intelligence feeds to actively identify compromised hosts and unauthorized account activity.

Anahtar Kavram

AWS threat detection and vulnerability management services function at different layers of the infrastructure, with Amazon Inspector performing software and reachability assessments, while Amazon GuardDuty performs active log-based threat monitoring.
Bu soruyu puanla