Soru

Zorluk: ZorSecurity Logging, Monitoring, and Auditing

A financial technology company is preparing for a security audit and must establish robust auditing and monitoring controls. The company needs to maintain a complete history of all API calls made within their AWS environment for compliance verification. Additionally, the security team needs to receive immediate notifications if any unauthorized modifications are made to network security configurations, such as security group rules.

Which of the following actions should the company take to meet these requirements? (Select TWO.)

  1. Enable AWS CloudTrail to capture and log API calls, storing them in a secure Amazon S3 bucket for compliance auditing.Cevap
  2. Create Amazon CloudWatch metric filters and alarms to notify security administrators in real-time when specific unauthorized API patterns occur in the logs.Cevap
  3. C
    Configure Amazon CloudWatch to record and verify all identity-based API requests to generate a cryptographic history for compliance audits.
  4. D
    Enable Amazon Inspector to continuously scan VPC Flow Logs and DNS logs to identify active network threats and unauthorized access patterns.
  5. E
    Request physical datacenter ingress records and hypervisor firewall logs from the AWS Security team to verify compliance with infrastructure controls.

Cevap

Enable AWS CloudTrail to capture API calls for compliance auditing, and create Amazon CloudWatch metric filters and alarms for real-time notifications.
To satisfy both requirements, the company must use AWS CloudTrail to record a complete log of all API operations (like creating or modifying resources) and deliver them to S3. They must also use Amazon CloudWatch Logs to collect the logs, create metric filters for unauthorized patterns (e.g., security group updates), and configure CloudWatch Alarms to send real-time alerts.

Adım Adım Çözüm

1
Identify the service responsible for auditing API requests and user activity.
AWS CloudTrail is identified as the service that records API activity and stores the history in an Amazon S3 bucket.
CloudTrail provides operational and risk auditing, governance, and compliance of your AWS account.
2
Identify the service responsible for monitoring metrics and setting up real-time alarms.
Amazon CloudWatch is identified as the service that can monitor logs, define metric filters, and configure alarms.
CloudWatch is used for monitoring resource utilization, log files, and triggering actions or alerts based on metrics.
3
Eliminate options that misrepresent the AWS Shared Responsibility Model or confuse services.
Options recommending Amazon Inspector for log analysis or requesting AWS-managed physical logs are eliminated.
Under the Shared Responsibility Model, physical infrastructure logs are AWS's responsibility and are not shared. Vulnerability scanning is distinct from active threat monitoring and log analysis.

Anahtar Kavram

AWS CloudTrail provides API auditing and activity logging, while Amazon CloudWatch provides performance metrics, log monitoring, and real-time alarms.
Bu soruyu puanla